A basic Direct Kernel Object Manipulation rootkit that removes a process from the EPROCESS list, hiding it from the Task Manager
-
Updated
Mar 26, 2019 - C
A basic Direct Kernel Object Manipulation rootkit that removes a process from the EPROCESS list, hiding it from the Task Manager
Kernel-mode process protection driver with user GUI
Educational Linux kernel rootkit PoC exploring DKOM, syscall hooking, stealth, observability and defensive detection
Offensive & defensive Linux kernel security research focused on rootkit behavior, observable artifacts and detection.
PsLoadedModuleList Unlinking through DKOM Manipulation
A DKOM hiding stuff for Linux, FreeBSD and NetBSD.
Modern C++20 / x64 MASM Windows Kernel Driver & Physical MMU Engine with PML4 CR3 Translation, DKOM Trace Scrubbers, Lockless Shared Memory, and Multi-Language (Python/Lua/PowerShell) Tooling.
Project for Computer Forensics and Cyber Crime Analysis Exam @ Polito - An interactive forensic serious game for identifying anti-forensic techniques across filesystem, memory, and network domains.
To associate your repository with the dkom topic, visit your repo's landing page and select "manage topics."