Hooked on Linux: Rootkit Taxonomy, Hooking Techniques and Tradecraft
ID: 9d457a5c-f132-5a3f-b4b7-297695995dfe
STIX ID: report--9d457a5c-f132-5a3f-b4b7-297695995dfe
Feed Name: Elastic Security Labs
This technical primer surveys Linux rootkits: their goals (persistence and stealth), evolution from userland LD_PRELOAD tricks to modern kernel-resident implants abusing eBPF and io_uring, and detailed hooking techniques (syscall table, inline prologue patching, VFS hooks, ftrace, kprobes, and more). It catalogs loader and payload models, cites real-world examples, discusses detection challenges and defensive opportunities, and previews a follow-up focused on detection engineering.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
