hardenedlinux/pagedrop ? reverse-engineered prompt

Reverse engineered prompt

Build me a Linux kernel module that can dump every executable page of a running process, even when the process is packed or keeps changing its code over time.

I want it to work on x86_64 and arm64, and to stay stealthy, so no VM and no ptrace. It should catch the right moments when pages become executable, keep multiple versions if the same address gets reused, and save the dumps with enough info to tell them apart later. It also needs to handle common things like exec, fork, clone, mremap, and protection changes without crashing on multithreaded programs.

Make it build cleanly against a current Linux kernel, and include a simple way to test it with packed binaries like UPX samples. If you need to check current kernel docs or APIs while wiring it up, go ahead and look them up online. Also keep the old user space prototype around if that helps explain or compare the behavior.

Are you gonna build this?

make sure you review the code using coderabbit

Try freeSponsored — opens CodeRabbit in a new tab