Furtex: Post-exploitation, rootkit and evasion research toolkit for Linux
Furtex is a specialized research toolkit designed for Linux post-exploitation and EDR evasion using io_uring and eBPF technologies. It provides a collection of tools for security researchers to test system defenses by bypassing traditional kernel hooks.
Why it matters
The toolkit demonstrates advanced methods for evading modern Linux security monitoring, highlighting significant challenges for cybersecurity defenders and EDR developers.
Post-exploitation and evasion research toolkit for Linux, built around io_uring and eBPF. No liburing, no frameworks, raw syscalls throughout.
For authorized research and red team engagements only. Don't run this on systems you don't own.
Furtex/ ├── io_uring/ raw io_uring ops: file, net, injection, exfil (13 tools) ├── bpf/ BPF map and program tooling (15 tools) ├── ebpf/ BPF-side programs and loaders (9 programs + 2 runners) ├── edrs/ EDR evasion and post-exploitation (75 tools) └── techniques/ Falco-specific bypass, all 25 default rules (13 tools) Requirements Toolchain
sudo apt install gcc clang make linux-headers- $( uname -r ) libbpf-dev bpftool Kernel versions
BTF must be enabled in the kernel ( CONFIG_DEBUG_INFO_BTF=y ) to run make vmlinux for ebpf/ programs.
On distros with older libc-dev headers (Ubuntu 22.04 etc.) you may need #ifndef IORING_OP_SOCKET / #define IORING_OP_SOCKET 45 . Already handled in this repo.
Get smarter about the news
Sign up free for a feed built around what you actually care about, Dive Deeper research on any story, and the full text of every article.
Create free accountAlready have an account? Sign in