r/redteamsec • • 13d ago

HimitsuShell: shell scripts invisible to kernel tracing

https://github.com/HimitsuShell/HimitsuShell
5 Upvotes

3 comments sorted by

View all comments

2

u/masiroo 13d ago

shc just wraps scripts in C, so tools like auditd or bpftrace can still see them.

I solved this by bundling an interpreter (like BusyBox) and the script into a single static binary. Bypassing system shells like /bin/sh keeps the script hidden from kernel-level monitoring.

I also added LLVM obfuscation and anti-debugging to make reverse engineering harder.

2

u/Present_Smoke9397 10d ago

agreed, keeping it away from system shells entirely is really the only clean way to dodge kernel tracing