logo

Hooked on Linux: Rootkit Detection Engineering

ID: 17426b60-f3d3-5900-93b6-6ca03929d1f0

STIX ID: report--17426b60-f3d3-5900-93b6-6ca03929d1f0

Feed Name: Elastic Security Labs

Threat Score
70/100

Date Published: 2026-04-02

Date Updated: 2026-04-27

...
...

This technical write-up analyzes Linux rootkits and detection engineering, demonstrating how trivial binary changes defeat static signatures and providing comprehensive behavioral detection strategies (Auditd rules, syslog patterns, process/file/syscall monitoring) for userland and kernel rootkits, eBPF and io_uring abuses, persistence (LD_PRELOAD, /etc/ld.so.preload, modprobe/modules-load, udev, systemd/cron), and defense-evasion techniques.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.