Singularity is an open-source Linux kernel rootkit designed for security research that demonstrates advanced evasion techniques. It uses the kernel's Ftrace mechanism to hook system calls and hide processes, files, and network activity without modifying the system call vector. The rootkit removes itself from module lists,

14m read timeFrom lwn.net
Post cover image

Sort: