Leveraging Landlock telemetry for Linux detection engineering
ID: 60b3dcab-0755-5a25-bce6-b6ee95b70d74
STIX ID: report--60b3dcab-0755-5a25-bce6-b6ee95b70d74
Feed Name: Sekoia.io Blog (archive)
Date Published: 2026-01-14
Date Updated: 2026-04-29
Author: Sekoia TDR, Erwan Chevalier and Guillaume C.
This report explains how to leverage the Linux Landlock LSM (introduced in kernel 5.13 with logging in 6.15) for host-level, behavior-based detections by capturing audit events (AUDIT_LANDLOCK_ACCESS/1423) that include Landlock-specific fields (e.g., domain and blockers). It shows practical examples of filesystem and network rule denials, how go-libaudit enriches events for ingestion into Sekoia’s SOC platform, and provides a Sigma rule to detect Landlock-triggered denials. Using a deliberately vulnerable web server and an LD_PRELOAD-based XZ scenario, the authors demonstrate how Landlock both constrains execution and produces high-signal telemetry for alerts, enabling defenders to build precise detections with low false positives.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
