r/hacking • • 5d ago

Github HimitsuShell: shell scripts invisible to kernel tracing

https://github.com/HimitsuShell/HimitsuShell
69 Upvotes

5 comments sorted by

21

u/masiroo 5d ago

shc just wraps scripts in C, so tools like auditd or bpftrace can still see them.

I solved this by bundling an interpreter (like BusyBox) and the script into a single static binary. Bypassing system shells like /bin/sh keeps the script hidden from kernel-level monitoring.

I also added LLVM obfuscation and anti-debugging to make reverse engineering harder.

15

u/_gipi_ 5d ago

yeah sure, static binary but it has still to do syscalls so I don't know how you think is not able to be intercepted by kernel tracing

6

u/masiroo 4d ago

You're right, syscalls can't be hidden.

I just meant that by embedding cat or ls, we don't need to pass arguments externally. This skips the execution events (like execve) that monitors look for.

13

u/realflow 5d ago

Hey Claude build decompiler