Patching and hooking the Linux kernel with only a stripped Linux kernel image.
-
Updated
Sep 1, 2026 - C
Patching and hooking the Linux kernel with only a stripped Linux kernel image.
KASLD derandomizes the Linux kernel's virtual and physical memory layout from a local process, using whatever its vantage — privilege, configuration, and confinement — allows.
Utility to find hidden Linux kernel modules
Linux & Android Kernel Vulnerability research and exploitation
Minimal no-libc Linux x86_64 ELF PoC build for Copy Fail (CVE-2026-31431)
Educational Linux kernel rootkit PoC exploring DKOM, syscall hooking, stealth, observability and defensive detection
Advanced kernel-native security framework to disrupt and prevent DNS-based breaches including C2 channels and tunneling with zero data loss. Combines TC, Netfilter, raw socket interception, BPF maps, and ring buffers, runs entirely on eBPF in the Linux kernel. Integrates with deep learning for advanced intelligent EDR
Curated Linux LPE corpus — 28 modules from 2016 to 2026, with detection rules. One command, safest-first root: skeletonkey --auto --i-know
Offensive & defensive Linux kernel security research focused on rootkit behavior, observable artifacts and detection.
Xen hypervisor protection for guest kernel memory integrity enforcement
plan-bound authorization architecture for governing privileged effects in untrusted computational agents.
Synapse is a lightweight Lua scripting environment designed for script development, testing, and debugging. It offers a rich set of features, stable performance, and an intuitive interface, making it suitable for both beginners and experienced programmers. The tool is built with a focus on reliability and ease of use, supporting various automation.
Project Chronos — eBPF/XDP covert timing-channel PoC for security research. Demonstrates kernel-level passive monitoring, IAT modulation, process masquerading & anti-forensics techniques. Built for Blue Team detection R&D.
Open-source hypervisor-based endpoint security. Ring -1 monitoring for Intel VT-x and AMD-V. Rootkit detection, DKOM, MSR guard, stealth EPT hooks.
Look for possible escape vectors from a container
An educational Secure Boot and Kernel Integrity Verification system demonstrating chain of trust, kernel signing, and protection against boot-level attacks using SHA-256 and RSA-2048.
A read-only Linux analyzer that maps kernel attack surface to the workloads using it and generates evidence-backed, reversible hardening plans.
ARM64 Android kernel research for the Samsung Galaxy S23 Ultra (SM-S918B)
To associate your repository with the kernel-security topic, visit your repo's landing page and select "manage topics."