logo

Investigating server compromises with cgroups: A Linux DFIR primer

ID: 0f80da15-bbfa-5a67-a03d-4b84a38d45a5

STIX ID: report--0f80da15-bbfa-5a67-a03d-4b84a38d45a5

Feed Name: Red Canary

Date Published: 2026-05-13

Date Updated: 2026-05-13

Author: Thomas Gardner

...
...

This blog post explains how Linux control groups (cgroups) can be used as process-enrichment telemetry for security investigations and detections. It covers cgroup structures under systemd and common container runtimes (Docker, Kubernetes, runc, Podman), shows how cgroup paths reveal context like service names, container/pod IDs and user sessions, demonstrates enrichment via Falco alerts in an investigation scenario, and provides guidance for collecting cgroup data and developing detections to improve investigative confidence and reduce false positives.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.