{"adoption": {"forks": 193, "observed_at": "2026-08-28T04:05:29.751964+00:00", "stars": 1736}, "canonical_url": "https://ross.abutalabs.com/products/singularity", "card": {"archived": false, "artifact_type": "library", "description": "Stealthy Linux Kernel Rootkit for modern kernels (6x)", "domain": ["security", "penetration-testing", "operating-systems"], "enriched": true, "function": ["security", "penetration-testing", "reverse-engineering"], "health_score": 72, "homepage": null, "language": "C", "license": "MIT", "license_family": "permissive", "maturity": "active", "member_repos": ["MatheuZSecurity/Singularity"], "name": "MatheuZSecurity/Singularity", "platform": ["c", "cli"], "pushed_at": "2026-06-11T17:22:31+00:00", "repo": "MatheuZSecurity/Singularity", "stars": 1736, "tags": ["rootkit", "lkm", "ftrace", "syscall-hooking", "edr-evasion", "ebpf-bypass", "proof-of-concept", "kernel-module", "red-team", "linux"], "topics": ["ftrace", "hooking", "kernel", "linux", "lkm", "rootkit", "syscall", "hidden", "poc"], "urls": [], "use_cases": ["study ftrace-based syscall hooking on modern kernels", "test EDR and eBPF runtime security tools like Falco and Tracee against kernel rootkits", "research rootkit stealth techniques for red team engagements", "evaluate LKRG and audit subsystem detection capabilities", "learn Linux kernel module development and hooking internals", "demonstrate process, file, and network connection hiding in a lab environment"], "what_it_is": "Singularity is a stealthy Linux kernel module (LKM) rootkit targeting modern 6.x kernels, using ftrace-based syscall hooking to hide processes, files, network connections, and itself. It is a proof-of-concept offensive security research tool that also demonstrates evasion of eBPF-based runtime security tools, LKRG, audit, and memory forensics mechanisms.", "when_to_avoid": ["you want to hide activity on systems you do not own or have authorization to test", "you need a defensive detection tool rather than an offensive PoC", "you target kernels older than 6.x", "you need production-grade, supported software"], "when_to_choose": ["you need a modern, actively maintained kernel rootkit PoC for 6.x kernels", "you are researching EDR/eBPF evasion at the kernel level", "you want to benchmark kernel runtime guards like LKRG", "you need a reference implementation of ftrace syscall hooking"]}, "data_as_of": "2026-08-30T08:39:29.467469+00:00", "members": [{"path": "/products/singularity", "repo": "MatheuZSecurity/Singularity", "role": "main", "score": 56}], "provenance": {"archived": {"kind": "observed", "observed_at": "2026-08-28T04:05:29.751964+00:00", "source": "github"}, "artifact_type": {"confidence": null, "enriched_at": "2026-08-30T03:30:39.856638+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "4110e5dec000e4d71159cb249c483d572b5ac886e996c316ff092267d23afd14", "fetched_at": "2026-08-28T04:05:29.751964+00:00", "kind": "readme", "missing": false, "url": "https://github.com/MatheuZSecurity/Singularity"}], "taxonomy_version": 1}, "description": {"kind": "observed", "observed_at": "2026-08-28T04:05:29.751964+00:00", "source": "github"}, "domain": {"confidence": null, "enriched_at": "2026-08-30T03:30:39.856638+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "4110e5dec000e4d71159cb249c483d572b5ac886e996c316ff092267d23afd14", "fetched_at": "2026-08-28T04:05:29.751964+00:00", "kind": "readme", "missing": false, "url": "https://github.com/MatheuZSecurity/Singularity"}], "taxonomy_version": 1}, "enriched": {"inputs": [], "kind": "computed", "method": "enrichment_status"}, "function": {"confidence": null, "enriched_at": "2026-08-30T03:30:39.856638+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "4110e5dec000e4d71159cb249c483d572b5ac886e996c316ff092267d23afd14", "fetched_at": "2026-08-28T04:05:29.751964+00:00", "kind": "readme", "missing": false, "url": "https://github.com/MatheuZSecurity/Singularity"}], "taxonomy_version": 1}, "health_score": {"inputs": ["days_since_push", "days_since_release", "archived"], "kind": "computed", "method": "health_v1"}, "homepage": {"kind": "observed", "observed_at": "2026-08-28T04:05:29.751964+00:00", "source": "github"}, "language": {"kind": "observed", "observed_at": "2026-08-28T04:05:29.751964+00:00", "source": "github"}, "license": {"kind": "observed", "observed_at": "2026-08-28T04:05:29.751964+00:00", "source": "github"}, "license_family": {"inputs": ["license"], "kind": "computed", "method": "license_family"}, "maturity": {"confidence": null, "enriched_at": "2026-08-30T03:30:39.856638+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "4110e5dec000e4d71159cb249c483d572b5ac886e996c316ff092267d23afd14", "fetched_at": "2026-08-28T04:05:29.751964+00:00", "kind": "readme", "missing": false, "url": "https://github.com/MatheuZSecurity/Singularity"}], "taxonomy_version": 1}, "member_repos": {"kind": "observed", "observed_at": "2026-08-28T04:05:29.751964+00:00", "source": "github"}, "name": {"kind": "observed", "observed_at": "2026-08-28T04:05:29.751964+00:00", "source": "github"}, "platform": {"confidence": null, "enriched_at": "2026-08-30T03:30:39.856638+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "4110e5dec000e4d71159cb249c483d572b5ac886e996c316ff092267d23afd14", "fetched_at": "2026-08-28T04:05:29.751964+00:00", "kind": "readme", "missing": false, "url": "https://github.com/MatheuZSecurity/Singularity"}], "taxonomy_version": 1}, "pushed_at": {"kind": "observed", "observed_at": "2026-08-28T04:05:29.751964+00:00", "source": "github"}, "repo": {"kind": "observed", "observed_at": "2026-08-28T04:05:29.751964+00:00", "source": "github"}, "stars": {"kind": "observed", "observed_at": "2026-08-28T04:05:29.751964+00:00", "source": "github"}, "tags": {"confidence": null, "enriched_at": "2026-08-30T03:30:39.856638+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "4110e5dec000e4d71159cb249c483d572b5ac886e996c316ff092267d23afd14", "fetched_at": "2026-08-28T04:05:29.751964+00:00", "kind": "readme", "missing": false, "url": "https://github.com/MatheuZSecurity/Singularity"}], "taxonomy_version": 1}, "topics": {"kind": "observed", "observed_at": "2026-08-28T04:05:29.751964+00:00", "source": "github"}, "urls": {"kind": "observed", "observed_at": "2026-08-28T04:05:29.751964+00:00", "source": "github"}, "use_cases": {"confidence": null, "enriched_at": "2026-08-30T03:30:39.856638+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "4110e5dec000e4d71159cb249c483d572b5ac886e996c316ff092267d23afd14", "fetched_at": "2026-08-28T04:05:29.751964+00:00", "kind": "readme", "missing": false, "url": "https://github.com/MatheuZSecurity/Singularity"}], "taxonomy_version": 1}, "what_it_is": {"confidence": null, "enriched_at": "2026-08-30T03:30:39.856638+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "4110e5dec000e4d71159cb249c483d572b5ac886e996c316ff092267d23afd14", "fetched_at": "2026-08-28T04:05:29.751964+00:00", "kind": "readme", "missing": false, "url": "https://github.com/MatheuZSecurity/Singularity"}], "taxonomy_version": 1}, "when_to_avoid": {"confidence": null, "enriched_at": "2026-08-30T03:30:39.856638+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "4110e5dec000e4d71159cb249c483d572b5ac886e996c316ff092267d23afd14", "fetched_at": "2026-08-28T04:05:29.751964+00:00", "kind": "readme", "missing": false, "url": "https://github.com/MatheuZSecurity/Singularity"}], "taxonomy_version": 1}, "when_to_choose": {"confidence": null, "enriched_at": "2026-08-30T03:30:39.856638+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "4110e5dec000e4d71159cb249c483d572b5ac886e996c316ff092267d23afd14", "fetched_at": "2026-08-28T04:05:29.751964+00:00", "kind": "readme", "missing": false, "url": "https://github.com/MatheuZSecurity/Singularity"}], "taxonomy_version": 1}}, "score": {"components": {"activity": 87, "longevity": 24, "rhythm": 35}, "computed_at": "2026-09-03T02:20:16.233290+00:00", "flags": ["no_releases"], "formula": "round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10)", "inputs": {"age_days": 345, "days_push": 83, "days_rel": null, "gap_med": null, "n_releases_24m": 0}, "score": 56, "version": 2}, "staleness": {"enrichment_outdated": false, "low_confidence": false, "scrape_days": 9, "stale_scrape": false}}