Skip to content
Moat or Bloat

ZeroShadow

Lightweight dynamic binary instrumentation engine for ELF files to hook functions, trace execution, and unpack malware

Library Rated 7 Oct 2026

Built by
Tetstack

Bloat

162/500

Where it landed on the scale

Bloat
0
Float
300
Moat
400

Summary

ZeroShadow is an early, single-developer security tool with a working demo against a dummy assembly stub and one tagged release. There's no sign of users, pricing or a documented path to revenue, and the approach (ptrace single-stepping) is easy to reproduce and very slow. It reads as a serious learning project more than a product.

Bloat · Not much here works or looks likely to last, yet.

Breakdown

Five measures, 100 points each. Open the receipts under any of them to see the posts and pages behind the points.

Viability

Is there a real problem, someone who would pay, and a market this builder can actually reach?

The problem is real in security research, but the project shows no user, no charging model, and it competes with free tools like Frida. Its own posts show it has only been tested on a toy stub.

18/100

Rubric 0–20No clear problem or user. A toy, a practice clone, or a solution looking for a problem.

Receipts (3)
  1. Pitches it as a lighter alternative to Frida for hooking and malware unpacking, with no mention of who would pay.

    “I finally present "ZeroShadow" think of it like an automated debugger. you can watch functions execute, read memory or change how an app behaves on the fly without needing the source code. it is a lightweight dynamic binary instrumentation engine for elf files. you use it to hook functions, trace execution paths and unpack malware without the massive overhead of heavy tools like frida. https:/”

    Post · @Tetstack · 25 Jun 2026 · open on Telegram (opens in a new tab)

  2. The only demonstrated result is detecting a SIGSEGV in a dummy assembly stub.

    “Okay some tweaks have been done and the output is amazing, mostly complete it has detected the memory fault by the dummy shadow_stub.s picasothedealer_com@cloudshell:~/ZeroShadow$ ./runtime/shadow_stub & sleep 0.5 && sudo ./ZeroShadow $! ./runtime/shadow_stub [6] 12577 [6]+ Stopped ./runtime/shadow_stub [*] booting ZeroShadow supervisor... [+] memory boundaries mapped. [*] hooki”

    Post · @Tetstack · 23 Jun 2026 · open on Telegram (opens in a new tab)

  3. The repo is MIT licensed with no homepage, which fits a free open-source tool with no revenue model.

    Checked 7 Oct 2026 · github.com/PicasoTheDeal/ZeroShadow (opens in a new tab)

Moat

What stops someone copying it?

Single-step ptrace tracing is a well-documented technique that others could rebuild quickly. The creator even notes it runs at about 10,000 steps per second and lists unsolved bypasses, so there's no defensible edge yet.

14/100

Rubric 0–20A thin wrapper or a clone that anyone here could rebuild in a weekend.

Receipts (3)
  1. Shows ptrace single-stepping is so slow that a short loop would take about 60 days, which is a basic design limit.

    “I messed up in the calculation, i forgot that when the c++ zeroshadow jumps in the way and because it uses ptrace it is going at approximately 10,000 ptrace steps per second. If according to the iteration i submitted which is 0x1FFFFFFFFF WHICH IS ABOUT 137 BILLION iteration, the assembly would have finished about maybe 30 sec, but because of that ptrace it would have took 60 days before it reache”

    Post · @Tetstack · 22 Jun 2026 · open on Telegram (opens in a new tab)

  2. Lists open weaknesses like signal races and TOCTOU, so the core isn't hardened.

    “So now, ZeroShadow is missing some things which are: The "Signal Race" (Asynchronous Bypassing) , Time-of-Check to Time-of-Use (TOCTOU) , Direct Memory Access (DMA) / Side-Channel , Signal Masking .”

    Post · @Tetstack · 23 Jun 2026 · open on Telegram (opens in a new tab)

  3. The creator is already considering moving from ptrace to eBPF, which suggests the current approach is provisional.

    “I would have used ptrace like my other project ZeroShadow and dSBOM but according to this source it's better to use the bpf functions, from eBPF Docs. source”

    Post · @Tetstack · 11 Aug 2026 · open on Telegram (opens in a new tab)

Momentum

Did the updates keep coming?

It was worked on across two months, but the repo's commits fall on just two days (June 24 and 25) and the only later sign is a discussion post in August. That's a short burst rather than steady shipping.

58/100

  • Sustained shipping18/60

    Worked on across 2 months.

  • Consistency40/40

    Updates in 2 of 2 months.

Receipts (2)
  1. Earliest post about it.

    “So guys basically i will be making a specific kind of project that i had in my mind i had the blueprint but never the time i will set KASCVE aside for a moment cuz i can't do it with this limitation. So this project is called ZeroShadow It's a a very small, low level security framework designed to protect compiled linux applications from memory corruption exploits specifically Return-Oriented ”

    Post · @Tetstack · 19 Jun 2026 · open on Telegram (opens in a new tab)

  2. Most recent post about it.

    “I would have used ptrace like my other project ZeroShadow and dSBOM but according to this source it's better to use the bpf functions, from eBPF Docs. source”

    Post · @Tetstack · 11 Aug 2026 · open on Telegram (opens in a new tab)

Infrastructure

Does a real, working product exist?

A working supervisor exists and caught a fault in a dummy stub, but the advertised hooking and unpacking aren't shown, and the author lists several unresolved bypasses. It's a thin working prototype.

58/100

  • It's live20/20

    https://github.com/PicasoTheDeal/ZeroShadow responded when checked.

  • HTTPS5/5

    Hosted on a platform (store, GitHub or Telegram), so HTTPS is the platform's.

  • Real product15/35

    There's a runnable supervisor and a published release, but the demo only shows it catching a crash in a toy program. Hooking, function tracing and unpacking, which the pitch promises, aren't shown working.

  • Own home0/10

    No home found.

  • Maintained15/15

    Last sign of shipping 2026-08-11.

  • Operations3/15

    It's a GitHub repo with one release and nothing else: no docs site, API, accounts, backend or second platform.

Receipts (5)
  1. https://github.com/PicasoTheDeal/ZeroShadow responded when checked.

    Checked 7 Oct 2026 · github.com/PicasoTheDeal/ZeroShadow (opens in a new tab)

  2. Shows the supervisor attaching to a stub process and flagging a hijack signal.

    “okay boom, it has detected it correctly. picasothedealer_com@cloudshell:~/ZeroShadow$ ./runtime/shadow_stub & sleep 0.5 && sudo ./ZeroShadow $! ./runtime/shadow_stub [6] 11834 [6]+ Stopped ./runtime/shadow_stub [*] booting ZeroShadow supervisor... [+] memory boundaries mapped. [*] hooking PID: 11834... [+] connected to prosses: 11834. monitoring loop active. [*] loaded 2 executab”

    Post · @Tetstack · 23 Jun 2026 · open on Telegram (opens in a new tab)

  3. Claims hooking, tracing and unpacking that none of the posted output demonstrates.

    “I finally present "ZeroShadow" think of it like an automated debugger. you can watch functions execute, read memory or change how an app behaves on the fly without needing the source code. it is a lightweight dynamic binary instrumentation engine for elf files. you use it to hook functions, trace execution paths and unpack malware without the massive overhead of heavy tools like frida. https:/”

    Post · @Tetstack · 25 Jun 2026 · open on Telegram (opens in a new tab)

  4. The repo description is only 'ELF binary tracing and instrumentation', with one release.

    Checked 7 Oct 2026 · github.com/PicasoTheDeal/ZeroShadow (opens in a new tab)

  5. One release and two commit days, with no homepage listed.

    Checked 7 Oct 2026 · github.com/PicasoTheDeal/ZeroShadow (opens in a new tab)

Sustainability

Is it being set up to last?

There's no payment path, pricing, privacy policy, terms or support contact, and the project is a solo hobby effort. The open-source release gives it some reach, but there's no sign it can fund or sustain itself.

14/100

  • Distribution10/30

    Versioned downloadable releases (1 on GitHub).

  • Payments0/15

    No payment provider found.

  • Pricing0/10

    No pricing found on the site.

  • Revenue0/5

    No post mentions customers, payments or revenue.

  • Privacy policy0/7

    No privacy policy found.

  • Terms0/5

    No terms of service found.

  • Support0/8

    No support contact found.

  • Commitment4/20

    The creator posted progress for a couple of months and is reflecting on a related project. There's no team, roadmap, dedicated community or funding, and the repo's last push was in June.

Receipts (5)
  1. Versioned downloadable releases (1 on GitHub).

    Checked 7 Oct 2026 · github.com/PicasoTheDeal/ZeroShadow (opens in a new tab)

  2. MIT-licensed open-source repo with no pricing or payment link.

    Checked 7 Oct 2026 · github.com/PicasoTheDeal/ZeroShadow (opens in a new tab)

  3. Mentions ZeroShadow and dSBOM as ongoing side projects, which shows continued interest.

    “I would have used ptrace like my other project ZeroShadow and dSBOM but according to this source it's better to use the bpf functions, from eBPF Docs. source”

    Post · @Tetstack · 11 Aug 2026 · open on Telegram (opens in a new tab)

  4. The last push to the repo was 2026-06-25, two days after launch.

    Checked 7 Oct 2026 · github.com/PicasoTheDeal/ZeroShadow (opens in a new tab)

  5. Set aside another project (KASCVE) to work on this, showing personal priority but no team.

    “So guys basically i will be making a specific kind of project that i had in my mind i had the blueprint but never the time i will set KASCVE aside for a moment cuz i can't do it with this limitation. So this project is called ZeroShadow It's a a very small, low level security framework designed to protect compiled linux applications from memory corruption exploits specifically Return-Oriented ”

    Post · @Tetstack · 19 Jun 2026 · open on Telegram (opens in a new tab)