└── README.md /README.md: -------------------------------------------------------------------------------- 1 | # RootKits List 2 | 3 | Updated the list with a more recent version and included a section for bootkits too 4 | 5 | ## rootkits 6 | 7 | https://github.com/bytecode77/living-off-the-land (fileless) 8 | https://github.com/D4stiny/spectre 9 | https://github.com/thesecretclub/window_hijack 10 | https://github.com/Mr-Un1k0d3r/SCShell 11 | https://github.com/realoriginal/doublepulsar-poc 12 | https://github.com/zouxianyu/PhysicalMemoryRW 13 | https://github.com/zouxianyu/KernelHiddenExecute 14 | https://github.com/isoadam/gina_public 15 | https://github.com/GayPig/driverless-basic-driver 16 | https://github.com/zerosum0x0/smbdoor 17 | https://github.com/Alex3434/wmi-static-spoofer 18 | https://github.com/KIDofot/BypassDriverDetection_And_Kill360Process 19 | https://github.com/longmode/UTKModule 20 | https://github.com/nkga/cheat-driver (read/write memory of arbitrary processes) 21 | https://github.com/lantaoxu/HWIDFaker (hwid fake) 22 | https://github.com/zerosum0x0/puppetstrings 23 | https://github.com/Synestraa/Highcall-Library (Highcall) 24 | https://github.com/Microwave89/drvtricks 25 | https://github.com/Psychotropos/xhunter1_privesc (XIGNCODE3) 26 | https://github.com/ionescu007/r0ak (RWE) 27 | https://github.com/cyberweapons/cyberweapons 28 | https://github.com/huoji120/AV-Killer 29 | https://github.com/Sqdwr/DeleteFile 30 | https://github.com/Sqdwr/DeleteFileByCreateIrp 31 | https://github.com/Mattiwatti/PPLKiller 32 | https://github.com/bfosterjr/ci_mod 33 | https://github.com/HoShiMin/EnjoyTheRing0 34 | https://github.com/hfiref0x/ZeroAccess 35 | https://github.com/hackedteam/driver-win32 36 | https://github.com/hackedteam/driver-win64 37 | https://github.com/csurage/Rootkit 38 | https://github.com/bowlofstew/rootkit.com 39 | https://github.com/Nervous/GreenKit-Rootkit 40 | https://github.com/bytecode-77/r77-rootkit 41 | https://github.com/Cr4sh/WindowsRegistryRootkit 42 | https://github.com/Alifcccccc/Windows-Rootkits 43 | https://github.com/Schnocker/NoEye 44 | https://github.com/christian-roggia/open-myrtus 45 | https://github.com/Cr4sh/DrvHide-PoC 46 | https://github.com/mstefanowich/SquiddlyDiddly2 47 | https://github.com/MalwareTech/FakeMBR 48 | https://github.com/Cr4sh/PTBypass-PoC 49 | https://github.com/psaneme/Kung-Fu-Malware 50 | https://github.com/hasherezade/persistence_demos 51 | https://github.com/MinhasKamal/TrojanCockroach 52 | https://github.com/akayn/kbMon 53 | 54 | 55 | 56 | ## bootkits 57 | https://github.com/btbd/umap 58 | https://github.com/DeviceObject/rk2017 59 | https://github.com/DeviceObject/ChangeDiskSector 60 | https://github.com/DeviceObject/Uefi_HelloWorld 61 | https://github.com/DeviceObject/ShitDrv 62 | https://github.com/DeviceObject/DarkCloud 63 | https://github.com/nyx0/Rovnix 64 | https://github.com/MalwareTech/TinyXPB 65 | https://github.com/m0n0ph1/Win64-Rovnix-VBR-Bootkit 66 | https://github.com/NextSecurity/Gozi-MBR-rootkit 67 | https://github.com/NextSecurity/vector-edk 68 | https://github.com/ahixon/booty 69 | 70 | 71 | ---------------------------------------------- 72 | 73 | ### Old List 74 | 75 | This may contain duplicates/cross over from the new list. 76 | But i intend to get that soprted in the near future. 77 | 78 | ``` 79 | 80 | https://github.com/bhassani/Alina/tree/master/Rootkit 81 | https://github.com/jiayy/lkm-rootkit 82 | https://github.com/ChristianPapathanasiou/apache-rootkit 83 | https://github.com/ChristianPapathanasiou/DEFCON-18-Android-rootkit-Mindtrick 84 | https://github.com/elfmaster/kprobe_rootkit 85 | https://github.com/ah450/rootkit 86 | https://github.com/Jyang772/HideProcessHookMDL 87 | https://github.com/Aarons100/Rootkits-Playground 88 | https://github.com/dluengo/yarr 89 | https://github.com/NotALaser/trk 90 | https://github.com/mempodippy/vlany 91 | http://www.ussrback.com/UNIX/penetration/rootkits/ 92 | https://github.com/Alifcccccc/Windows-Rootkits 93 | https://packetstormsecurity.com/files/125240/Azazel-Userland-Rootkit.html 94 | https://github.com/islamTaha12/Python-Rootkit 95 | https://github.com/Eterna1/puszek-rootkit 96 | https://github.com/juxing/AdoreForAndroid 97 | https://github.com/HackerFantastic/Public/tree/master/rootkits 98 | https://github.com/m0nad/Diamorphine 99 | https://github.com/maK-/maK_it-Linux-Rootkit 100 | https://github.com/RagingGrim/Rootkit/tree/master/Rootkit 101 | https://github.com/NexusBots/Umbreon-Rootkit 102 | https://github.com/josephjkong/designing-bsd-rootkits 103 | https://github.com/citypw/suterusu/ 104 | https://citypw.blogspot.gr/2014/08/an-awesome-linux-kernel-rootkit-suterusu.html 105 | https://github.com/Cr4sh/WindowsRegistryRootkit 106 | https://packetstormsecurity.com/files/139665/Vlany-Linux-LD_PRELOAD-Rootkit.html 107 | https://github.com/JReFrameworker/JReFrameworker 108 | https://packetstormsecurity.com/files/128945/Xingyiquan-Linux-2.6.x-3.x-Rootkit.html 109 | https://packetstormsecurity.com/files/118317/Linux-2.6-Kernel-proc-Rootkit-Backdoor.html 110 | https://packetstormsecurity.com/files/108286/KBeast-Kernel-Beast-Linux-Rootkit-2012.html 111 | https://packetstormsecurity.com/files/110942/Jynx-Kit-Release-2.html 112 | https://packetstormsecurity.com/files/25071/_root_040.zip.html 113 | https://github.com/bones-codes/the_colonel 114 | https://github.com/x0r1/jellyfish 115 | https://github.com/ecume/simple-rootkit 116 | https://github.com/Nervous/GreenKit-Rootkit 117 | https://github.com/cloudsec/brootkit 118 | https://github.com/unix-thrust/beurk 119 | https://github.com/NextSecurity/Gozi-MBR-rootkit 120 | https://github.com/rbertin/basic-rootkit 121 | https://github.com/miagilepner/porny 122 | https://turbochaos.blogspot.gr/2013/09/linux-rootkits-101-1-of-3.html 123 | https://github.com/r00tkillah/HORSEPILL 124 | https://github.com/matteomattia/moo_rootkit 125 | https://github.com/ivyl/rootkit 126 | https://github.com/enzolovesbacon/inficere 127 | https://github.com/hiteshd/Android-Rootkit 128 | https://github.com/QuokkaLight/rkduck 129 | https://github.com/0xroot/whitesnow 130 | https://github.com/falk3n/subversive 131 | https://github.com/nnewson/km/tree/master/src 132 | https://github.com/Cr4sh/DrvHide-PoC 133 | https://github.com/Christian-Roggia/open-myrtus/tree/master/rootkit 134 | https://github.com/PoppySeedPlehzr/rookit_playground/tree/master/rootkits 135 | https://github.com/a7vinx/liinux 136 | https://github.com/osiris123/CDriver_Loader 137 | https://github.com/varshapaidi/Kernel_Rootkit 138 | https://github.com/karol-gruszczyk/win-rootkit 139 | https://github.com/hanj4096/wukong 140 | https://github.com/uzyszkodnik/rootkit 141 | https://github.com/kacheo/KernelRootkit 142 | https://github.com/rvillordo/libpreload 143 | https://github.com/soad003/rootkit 144 | https://github.com/NinnOgTonic/Out-of-Sight-Out-of-Mind-Rootkit 145 | https://github.com/HeapLock/THOR 146 | https://github.com/ring-1/zendar 147 | https://github.com/amanone/amark 148 | https://github.com/majdi/deadlands 149 | https://github.com/cccssw/JynKbeast 150 | https://github.com/joshimhoff/toykit 151 | https://github.com/pasv/Z34107 152 | https://github.com/maK-/Keylogger-lkm 153 | https://github.com/Aearnus/syscall-rootkit 154 | https://github.com/schischi/slrk 155 | ``` 156 | --------------------------------------------------------------------------------