*awesome-linux-rootkits*
Awesome 🔑 feature table

#linux #awesome #rootkit #linux_kernel #awesome_list #lkm_rootkit

Environment:

- CPU architecture
- Kernel/User mode (or mixed)

Core capabilities:

- Persistency
- Management interface
- Altering system (library) behavior

Stealth capabilities:

- Detection evasion
- System logs cleaning (filtering)

Hiding stuff capabilities:

- Hiding of files and directories
- Hiding (tampering) of file contents
- Hiding of processes and process trees
- Hiding of network connections and activity
- Hiding of process accounting information (like CPU usage)

Additional functions:

- Keylogger
- Backdoor/shell
- Gaining priveleges

github.com/milabs/awesome-linu