Stars
surftrace is a tool that allows you to surf the linux kernel
ebpfkit-monitor is a tool that detects and protects against eBPF powered rootkits
Examples for aquasecurity/libbpfgo and cilium/ebpf
Linux system exploration and troubleshooting tool with first class support for containers
eBPF-based Security Observability and Runtime Enforcement
[WIP] 整理过去我和K8s、容器、虚拟化相关的分享 🧐
Scans a given process. Recognizes and dumps a variety of potentially malicious implants (replaced/injected PEs, shellcodes, hooks, in-memory patches).
程序员延寿指南 | A programmer's guide to live longer
ETWProcessMon2 is for Monitoring Process/Thread/Memory/Imageloads/TCPIP via ETW + Detection for Remote-Thread-Injection & Payload Detection by VirtualMemAlloc Events (in-memory) etc.
PoC memory injection detection agent based on ETW, for offensive and defensive research purposes
Like0x / SharpBlock
Forked from CCob/SharpBlockA method of bypassing EDR's active projection DLL's by preventing entry point exection
Custom Command and Control (C3). A framework for rapid prototyping of custom C2 channels, while still providing integration with existing offensive toolkits.
📦 Make security testing of K8s, Docker, and Containerd easier.
C# 读取本机对外RDP连接记录和其他主机对该主机的连接记录,从而在内网渗透中获取更多可通内网网段信息以及定位运维管理人员主机