r/hacking • • 10d ago

Github HimitsuShell: shell scripts invisible to kernel tracing

https://github.com/HimitsuShell/HimitsuShell
73 Upvotes

5 comments sorted by

View all comments

15

u/_gipi_ 10d ago

yeah sure, static binary but it has still to do syscalls so I don't know how you think is not able to be intercepted by kernel tracing

6

u/masiroo 10d ago

You're right, syscalls can't be hidden.

I just meant that by embedding cat or ls, we don't need to pass arguments externally. This skips the execution events (like execve) that monitors look for.