Leveraging Landlock telemetry for Linux detection engineering
ID: 670fb812-9485-523f-9b9f-4ab2177c84ff
STIX ID: report--670fb812-9485-523f-9b9f-4ab2177c84ff
Feed Name: Sekoia.com
This report evaluates the Linux Landlock LSM as both a hardening mechanism and a source of high-fidelity telemetry for detection engineering: it demonstrates filesystem and network denial events with go-libaudit-enriched logs, shows how those events can be used to write Sigma rules, and illustrates use cases including a vulnerable Go web server and an LD_PRELOAD-based simulation. The report also references the XZ Utils supply-chain compromise (CVE-2024-3094) to show attacker targeting of Landlock-enabled builds and highlights how Landlock-denied actions provide actionable alerts for SOCs.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
