Android Loadable Kernel Modules (android-lkms) are mostly used for reversing and debugging on controlled systems/emulators. These modules include antiptrace for simple ptrace hooking, open-read-write for hooking functions to track file interactions of malware, and antiunlink to prevent specific package names from unlinking files in their directories. Warning: Not recommended for production environments as they may slow down qemu environments and have unexpected outcomes.
FEATURES
EXPLORE BY TAGS
SIMILAR TOOLS
CrowdStrike Falcon is a unified cybersecurity platform providing complete protection through its AI-native XDR platform.
Toolkit for building custom minimal, immutable Linux distributions with secure defaults.
A cross-platform security application that functions as a laptop kill cord, automatically locking or shutting down your computer when physically separated from you via a USB connection.
Kunai is a Linux-based system monitoring tool that provides real-time monitoring and threat hunting capabilities.
A free endpoint security tool for host investigative capabilities to find signs of malicious activity through memory and file analysis.
Comprehensive endpoint protection solution providing advanced threat detection, proactive defense, and efficient management.
Monitor WMI consumers and processes for potential malicious activity
GravityZone is a unified endpoint security and analytics platform that provides risk assessment, threat prevention, and incident response capabilities.
PINNED

Mandos
Fractional CISO service that helps B2B companies implement security leadership to win enterprise deals, achieve compliance, and develop strategic security programs.

Checkmarx SCA
A software composition analysis tool that identifies vulnerabilities, malicious code, and license risks in open source dependencies throughout the software development lifecycle.

Orca Security
A cloud-native application protection platform that provides agentless security monitoring, vulnerability management, and compliance capabilities across multi-cloud environments.

DryRun
A GitHub application that performs automated security code reviews by analyzing contextual security aspects of code changes during pull requests.