*awesome-linux-rootkits*
Awesome 🔑 feature table
#linux #awesome #rootkit #linux_kernel #awesome_list #lkm_rootkit
Environment:
- CPU architecture
- Kernel/User mode (or mixed)
Core capabilities:
- Persistency
- Management interface
- Altering system (library) behavior
Stealth capabilities:
- Detection evasion
- System logs cleaning (filtering)
Hiding stuff capabilities:
- Hiding of files and directories
- Hiding (tampering) of file contents
- Hiding of processes and process trees
- Hiding of network connections and activity
- Hiding of process accounting information (like CPU usage)
Additional functions:
- Keylogger
- Backdoor/shell
- Gaining priveleges
https://github.com/milabs/awesome-linux-rootkits#hear_no_evil-kernel-mode-rootkits