Linux Loadable Kernel Module (LKM) based rootkit (ring-0), capable of hiding itself, processes/implants, rmmod proof, has ability to bypass infamous rkhunter antirootkit.
-
Updated
Dec 6, 2025 - C
Linux Loadable Kernel Module (LKM) based rootkit (ring-0), capable of hiding itself, processes/implants, rmmod proof, has ability to bypass infamous rkhunter antirootkit.
A collection of memory forensics case studies performed using Volatility. This repository contains malware investigations, rootkit analysis, process analysis, network artifact analysis and findings from different memory samples.
Add a description, image, and links to the kernel-mode-rootkit topic page so that developers can more easily learn about it.
To associate your repository with the kernel-mode-rootkit topic, visit your repo's landing page and select "manage topics."