Hooked on Linux: Rootkit Detection Engineering
ID: 17426b60-f3d3-5900-93b6-6ca03929d1f0
STIX ID: report--17426b60-f3d3-5900-93b6-6ca03929d1f0
Feed Name: Elastic Security Labs
Threat Score
This technical write-up analyzes Linux rootkits and detection engineering, demonstrating how trivial binary changes defeat static signatures and providing comprehensive behavioral detection strategies (Auditd rules, syslog patterns, process/file/syscall monitoring) for userland and kernel rootkits, eBPF and io_uring abuses, persistence (LD_PRELOAD, /etc/ld.so.preload, modprobe/modules-load, udev, systemd/cron), and defense-evasion techniques.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
