Investigating server compromises with cgroups: A Linux DFIR primer
ID: 0f80da15-bbfa-5a67-a03d-4b84a38d45a5
STIX ID: report--0f80da15-bbfa-5a67-a03d-4b84a38d45a5
Feed Name: Red Canary
This blog post explains how Linux control groups (cgroups) can be used as process-enrichment telemetry for security investigations and detections. It covers cgroup structures under systemd and common container runtimes (Docker, Kubernetes, runc, Podman), shows how cgroup paths reveal context like service names, container/pod IDs and user sessions, demonstrates enrichment via Falco alerts in an investigation scenario, and provides guidance for collecting cgroup data and developing detections to improve investigative confidence and reduce false positives.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
