• Skip to main content
  • Skip to primary sidebar
  • Skip to footer
  • Home
  • About Darknet
  • Hacking Tools
  • Popular Posts
  • Darknet Archives
  • Contact Darknet
    • Advertise
    • Submit a Tool
Darknet – Hacking Tools, Hacker News & Cyber Security

Darknet - Hacking Tools, Hacker News & Cyber Security

Darknet is your best source for the latest hacking tools, hacker news, cyber security best practices, ethical hacking & pen-testing.

Caracal – Rust eBPF Rootkit for Stealthy Post-Exploitation

July 7, 2025

Views: 712

Caracal is a new Rust-based eBPF (extended Berkeley Packet Filter) rootkit that provides a stealth layer for red team operators by hiding userland processes and kernel-level BPF programs from traditional monitoring tools. It is designed for advanced post-exploitation phases where persistence, evasion, and concealment are critical.

Caracal - Rust eBPF Rootkit for Stealthy Post-Exploitation

Overview

Caracal targets Linux environments by manipulating the eBPF subsystem, a powerful kernel-based packet filtering and tracing engine. By exploiting visibility gaps in BPF observability, it can cloak processes and kernel hooks from detection mechanisms such as ps, top, ls /proc, and BPF-specific tools like bpftool and bpftop.

The tool works by loading eBPF programs via privileged Rust binaries that directly interact with kernel internals. Once deployed, Caracal actively interferes with kernel telemetry and hides its artefacts from process listing and introspection tools. It complements staging tools like feroxbuster and post-exploitation payloads such as Sliver by enabling low-noise operator presence in hostile environments.

Key Features

  • Written in Rust for safety, speed, and memory integrity
  • Hides eBPF programs and maps from bpftool enumeration
  • Conceals userland processes from ps, top, procfs queries
  • Modular architecture for flexible deployment
  • Open source under GPLv3

Red Team Relevance

Modern detection strategies increasingly rely on kernel-level telemetry and real-time monitoring using eBPF agents. Caracal targets that exact surface. It provides advanced evasion capability in post-compromise situations where traditional rootkits are too noisy or signatured. It can be deployed as a next-gen persistence mechanism or as an in-memory staging vector post shell access.

In red team operations simulating nation-state actors or advanced persistent threats (APTs), tools like Caracal provide realism by mimicking stealth techniques that evade both behavioural and signature-based endpoint detection. This is especially relevant in environments where defenders deploy eBPF-based observability platforms such as Cilium or Falco.

Detection and Mitigation Considerations

Currently, Caracal evades most standard detection techniques. However, defenders should monitor:

  • Unusual kernel memory allocations not mapped to known processes
  • Discrepancies between procfs and telemetry pipelines
  • Hidden processes not correlated with auditd logs
  • Changes in eBPF program counts or unverified program loading

Advanced monitoring using memory forensics tools or kernel patch integrity frameworks may eventually help uncover such stealth layers, but this remains an open problem in active defence.

Conclusion

Caracal represents a leap forward in stealth tooling for red teamers and adversary simulation. With its novel use of Rust and kernel eBPF manipulation, it operates well below the radar of most commercial endpoint detection systems. As defenders increase reliance on eBPF-based telemetry, offensive operators must adapt—and Caracal is a powerful step in that direction.

You can read more or download caracal here: github.com/adgaultier/caracal

Related Posts:

  • XRayC2 - Weaponizing AWS X-Ray for Covert Command…
  • RustRedOps - Rust Native Offensive Toolkit…
  • Tyton - Kernel-Mode Rootkit Hunter for Linux
  • BlockEDRTraffic - EDR Evasive Lateral Movement Tool
  • Best Open Source HIDS Tools for Linux in 2025…
  • CloudConqueror - AWS CloudControl API Attack Surface…
Share
Tweet
Share
Buffer
WhatsApp
Email

Filed Under: Hacking Tools Tagged With: ebpf, red team



Primary Sidebar

Search Darknet

  • Email
  • Facebook
  • LinkedIn
  • RSS
  • Twitter

Advertise on Darknet

Latest Posts

Reconnoitre - Open-Source Reconnaissance and Service Enumeration Tool

Reconnoitre – Open-Source Reconnaissance and Service Enumeration Tool

Views: 308

Reconnoitre is an open-source reconnaissance tool that automates multithreaded information gathering … ...More about Reconnoitre – Open-Source Reconnaissance and Service Enumeration Tool

Scanners-Box - Open-Source Reconnaissance and Scanning Toolkit

Scanners-Box – Open-Source Reconnaissance and Scanning Toolkit

Views: 486

Scanners-Box is an open-source, community-curated collection of scanners and reconnaissance … ...More about Scanners-Box – Open-Source Reconnaissance and Scanning Toolkit

Red Teaming LLMs 2025 - Offensive Security Meets Generative AI

Red Teaming LLMs 2025 – Offensive Security Meets Generative AI

Views: 522

As enterprises deploy large language models (LLMs) at scale, the offensive security discipline of … ...More about Red Teaming LLMs 2025 – Offensive Security Meets Generative AI

gitlab-runner-research - PoC for abusing self-hosted GitLab runners

gitlab-runner-research – PoC for abusing self-hosted GitLab runners

Views: 337

gitlab-runner-research is a proof-of-concept repository and write-up that demonstrates how attackers … ...More about gitlab-runner-research – PoC for abusing self-hosted GitLab runners

mcp-scanner - Python MCP Scanner for Prompt-Injection and Insecure Agents

mcp-scanner – Python MCP Scanner for Prompt-Injection and Insecure Agents

Views: 589

mcp-scanner is an open-source Python tool that scans Model Context Protocol (MCP) servers and agent … ...More about mcp-scanner – Python MCP Scanner for Prompt-Injection and Insecure Agents

Deepfake-as-a-Service 2025 - How Voice Cloning and Synthetic Media Fraud Are Changing Enterprise Defenses

Deepfake-as-a-Service 2025 – How Voice Cloning and Synthetic Media Fraud Are Changing Enterprise Defenses

Views: 672

Deepfake operations have matured into a commercial model that attackers package as … ...More about Deepfake-as-a-Service 2025 – How Voice Cloning and Synthetic Media Fraud Are Changing Enterprise Defenses

Topics

  • Advertorial (28)
  • Apple (46)
  • Cloud Security (8)
  • Countermeasures (231)
  • Cryptography (85)
  • Dark Web (4)
  • Database Hacking (89)
  • Events/Cons (7)
  • Exploits/Vulnerabilities (433)
  • Forensics (64)
  • GenAI (12)
  • Hacker Culture (10)
  • Hacking News (236)
  • Hacking Tools (708)
  • Hardware Hacking (82)
  • Legal Issues (179)
  • Linux Hacking (74)
  • Malware (241)
  • Networking Hacking Tools (352)
  • Password Cracking Tools (107)
  • Phishing (41)
  • Privacy (219)
  • Secure Coding (119)
  • Security Software (235)
  • Site News (51)
    • Authors (6)
  • Social Engineering (37)
  • Spammers & Scammers (76)
  • Stupid E-mails (6)
  • Telecomms Hacking (6)
  • UNIX Hacking (6)
  • Virology (6)
  • Web Hacking (384)
  • Windows Hacking (171)
  • Wireless Hacking (45)

Security Blogs

  • Dancho Danchev
  • F-Secure Weblog
  • Google Online Security
  • Graham Cluley
  • Internet Storm Center
  • Krebs on Security
  • Schneier on Security
  • TaoSecurity
  • Troy Hunt

Security Links

  • Exploits Database
  • Linux Security
  • Register – Security
  • SANS
  • Sec Lists
  • US CERT

Footer

Most Viewed Posts

  • Brutus Password Cracker Hacker – Download brutus-aet2.zip AET2 (2,395,016)
  • Darknet – Hacking Tools, Hacker News & Cyber Security (2,173,814)
  • Top 15 Security Utilities & Download Hacking Tools (2,097,292)
  • 10 Best Security Live CD Distros (Pen-Test, Forensics & Recovery) (1,200,141)
  • Password List Download Best Word List – Most Common Passwords (934,346)
  • wwwhack 1.9 – wwwhack19.zip Web Hacking Software Free Download (777,068)
  • Hack Tools/Exploits (673,985)
  • Wep0ff – Wireless WEP Key Cracker Tool (531,053)

Search

Recent Posts

  • Reconnoitre – Open-Source Reconnaissance and Service Enumeration Tool November 10, 2025
  • Scanners-Box – Open-Source Reconnaissance and Scanning Toolkit November 7, 2025
  • Red Teaming LLMs 2025 – Offensive Security Meets Generative AI November 5, 2025
  • gitlab-runner-research – PoC for abusing self-hosted GitLab runners November 3, 2025
  • mcp-scanner – Python MCP Scanner for Prompt-Injection and Insecure Agents October 31, 2025
  • Deepfake-as-a-Service 2025 – How Voice Cloning and Synthetic Media Fraud Are Changing Enterprise Defenses October 29, 2025

Tags

apple botnets computer-security darknet Database Hacking ddos dos exploits fuzzing google hacking-networks hacking-websites hacking-windows hacking tool Information-Security information gathering Legal Issues malware microsoft network-security Network Hacking Password Cracking pen-testing penetration-testing Phishing Privacy Python scammers Security Security Software spam spammers sql-injection trojan trojans virus viruses vulnerabilities web-application-security web-security windows windows-security Windows Hacking worms XSS

Copyright © 1999–2025 Darknet All Rights Reserved · Privacy Policy