Skip to content
/ elfdoc Public

Proof of concept heuristic detection for common ELF infection algorithms.

Notifications You must be signed in to change notification settings

sad0p/elfdoc

Repository files navigation

elfdoc

Proof of concept heuristic detection for common ELF infection algorithms.

Detection capability

  • Entry point modification.
  • Embedded payloads.
  • Mangled Section Header.
  • PT_NOTE infection.

Build (requires cmake)

mkdir build; cd build; cmake .. ; make

Run

Single file

elfdoc <path-to-file>

Directory scan bash for-loop.

for file in .; do elfdoc $file ; done

About

Proof of concept heuristic detection for common ELF infection algorithms.

Topics

Resources

Stars

Watchers

Forks

Releases

No releases published

Packages

No packages published