h3xduck / TripleCross

A Linux eBPF rootkit with a backdoor, C2, library injection, execution hijacking, persistence and stealth capabilities.

Geek Repo:Geek Repo

Github PK Tool:Github PK Tool

Activate the userspace runtime config for active ebpf modules from the remote client connected to the backdoor.

h3xduck opened this issue · comments

Activate the userspace runtime config for active ebpf modules from the remote client connected to the backdoor.

This is already done via the -u and -a modes of the rootkit client, but It would be cool to control which specific ebpf programs are active instead of just all or none.