Mitigating New Vulnerabilities with owLSM
ID: a2ac6a8a-bf59-5042-a202-46093a4c19f8
STIX ID: report--a2ac6a8a-bf59-5042-a202-46093a4c19f8
Feed Name: LevelBlue SpiderLabs Blog
This blog-style technical post demonstrates exploiting the CrackArmor AppArmor vulnerabilities to allow an unprivileged user to remove AppArmor profiles and shows how the open-source owLSM agent can detect the relevant write events and immediately prevent exploitation by applying a Sigma-like rule that blocks non-root writes to /sys/kernel/security/apparmor and kills the SUID process; the article includes an example event JSON, the rule text, and guidance on using owLSM as an interim mitigation when patches are not yet available.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
