BPFDoor Scanner
ID: 9c693937-0233-5e18-8a44-48bdf1d85262
STIX ID: report--9c693937-0233-5e18-8a44-48bdf1d85262
Feed Name: Elastic Security Labs
This document is a concise guide for a Python/Docker-based scanner that detects BPFDoor-infected hosts, detailing required Linux capabilities (CAP_NET_BIND_SERVICE, CAP_NET_RAW), Docker image build and run instructions, command-line options (e.g., --target-ip, --source-ip, ports, timeouts), and local execution via Poetry, with notes about needing elevated privileges for low source ports and a reference to Elastic Security’s in-depth BPFDoor analysis.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
