logo

Hooked on Linux: Rootkit Taxonomy, Hooking Techniques and Tradecraft

ID: 9d457a5c-f132-5a3f-b4b7-297695995dfe

STIX ID: report--9d457a5c-f132-5a3f-b4b7-297695995dfe

Feed Name: Elastic Security Labs

Threat Score
70/100

Date Published: 2026-03-05

Date Updated: 2026-04-27

...
...

This technical primer surveys Linux rootkits: their goals (persistence and stealth), evolution from userland LD_PRELOAD tricks to modern kernel-resident implants abusing eBPF and io_uring, and detailed hooking techniques (syscall table, inline prologue patching, VFS hooks, ftrace, kprobes, and more). It catalogs loader and payload models, cites real-world examples, discusses detection challenges and defensive opportunities, and previews a follow-up focused on detection engineering.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.