Detection primitives for eBPF rootkits
ID: 5fca4fce-feae-5f46-a6c1-77c452556fd6
STIX ID: report--5fca4fce-feae-5f46-a6c1-77c452556fd6
Feed Name: Datadog Security Labs
This report analyzes real-world Linux eBPF rootkits (VoidLink, LinkPro, Atomic Arch), describing how they abuse rare eBPF helpers (bpf_probe_write_user, bpf_override_return, bpf_send_signal) and kprobes/tracepoints to hide network sockets, conceal eBPF programs from enumeration, and kill debuggers; it explains the kernel mechanics behind each technique and presents a reliable defensive approach of capturing load-time eBPF fingerprints (program type, helper bitmap, metadata) to detect such rootkits before they can attach and evade inspection.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
