logo

Detecting and Capturing Kernel Modules with Tracee and eBPF

ID: c328f404-88c3-5e0c-b24e-d16497eace45

STIX ID: report--c328f404-88c3-5e0c-b24e-d16497eace45

Feed Name: Aqua Security Blog

Threat Score
70/100

Date Published: 2022-07-20

Date Updated: 2026-04-26

...
...

This blog describes the risks posed by malicious Linux kernel modules (kernel rootkits), how attackers load modules from memory to evade filesystem-based detection, the heightened danger for containerized/cloud environments (host escape and cross-container compromise), and demonstrates how Tracee can detect and dump volatile kernel modules for forensic analysis; it also references TeamTNT and the Diamorphine rootkit and mentions Aqua CNDR detection capabilities.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.