Ross ROSS = Recommend OSS · open-source software intelligence for agents

bytecode77/r77-rootkit

Fileless ring 3 rootkit with installer and persistence that hides processes, files, network connections, etc. observed · 2026-08-28

github.com/bytecode77/r77-rootkit · homepage · C · MIT (permissive) observed · 2026-08-28

Health v2 · maintenance only

75/100

  • Activity 94
  • Release rhythm 35
  • Longevity 100

Flags: no_releases

How is this computed?

round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10) — computed 2026-09-03. Adoption (stars, forks) is never an input.

  • gap_med: n/a
  • age_days: 3181
  • days_rel: n/a
  • days_push: 36
  • n_releases_24m: 0

Full methodology

Adoption not part of the score

2191 stars · 460 forks observed · 2026-08-28

What it is AI-extracted, prompt v1, taxonomy v1, 2026-08-30, confidence not recorded

r77 is a fileless ring 3 (userland) rootkit for Windows that hides files, processes, registry keys, services, and network connections using a configurable prefix-based hiding system. It includes an installer with persistence, shellcode-based fileless deployment, and AV/EDR evasion techniques such as AMSI bypass and ntdll unhooking.

Use cases

  • hide processes from task manager
  • study rootkit techniques on windows
  • test EDR detection of fileless malware
  • hide files and registry keys by prefix
  • evaluate antivirus evasion via AMSI bypass
  • research userland rootkit injection methods

When to choose

  • you need an open-source reference rootkit for security research or red-team training
  • you want to test AV/EDR detection capabilities against fileless techniques
  • you need a configurable userland hiding mechanism on Windows

When to avoid

  • you need a kernel-mode (ring 0) rootkit
  • you want defensive-only tooling without offensive capabilities
  • your target platform is Linux or macOS
  • you require stealth against hardened, modern EDR environments

Facets

application · maturity active

security reverse-engineering penetration-testing security penetration-testing windows operating-systems windows c rootkit fileless av-evasion amsi-bypass dll-unhooking process-hiding red-team userland-rootkit

2 sources

Member repositories

RepositoryRoleHealth v2
bytecode77/r77-rootkitmain75

For agents

markdown · JSON · MCP: product_card(name="bytecode77/r77-rootkit")

Data as of 2026-08-30T08:39:29.467469+00:00 · Report a problem