{"repo":"Idov31/Nidhogg","free":true,"listed":false,"github":"https://github.com/Idov31/Nidhogg","clone":"git clone https://github.com/Idov31/Nidhogg.git","description":"Windows rootkit for Intel x64 with 25+ features, demonstrating rootkit techniques compatible with all Windows 10 and Windows 11 versions.","language":"C++","stars":2463,"topics":["cpp","cybersecurity","infosec","kernel","red-team","redteam","rootkit","windows","windows-rootkits","cyber-security"],"license":"GPL-3.0","category":"security-tools","readme_excerpt":"Nidhogg Nidhogg is a multi-functional rootkit to showcase the variety of operations that can be done from kernel space. The goal of Nidhogg is to provide an all-in-one and easy-to-use rootkit with multiple helpful functionalities for operations. Besides that, it can also easily be integrated with your C2 framework. Nidhogg can work on any version of x64 Windows 10 and Windows 11. This repository contains a kernel driver with a C++ program to communicate with it. If you want to know more, check out the wiki for a detailed explanation. Current Features [!IMPORTANT] All the features have been fully tested up to Windows 11 25H2. If you encounter a problem, please open an issue after checking there isn't already an open issue. - Process hiding and unhiding - Process elevation - Process protection (anti-kill and dumping) - Bypass memory scanners (e.g. pe-sieve) - Thread hiding and unhiding - Thread protection (anti-kill) - File protection (anti-deletion and overwriting) - Registry keys and values protection (anti-deletion and overwriting) - Registry keys and values hiding - Listing currently protected or hidden processes, threads, files, ports, registry keys and values - Function patching - Built-in AMSI bypass - Built-in ETW patch - Process signature (PP/PPL) modification - Can be reflectively loaded - Shellcode Injection - APC - NtCreateThreadEx - DLL Injection - APC - NtCreateThreadEx - Listing kernel callbacks - ObCallbacks - Process and thread creation routines - Image loading","default_branch":null,"files":null,"tree":[],"storefront":"/r/Idov31","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/Idov31/Nidhogg/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}