Detecting and Capturing Kernel Modules with Tracee and eBPF
ID: c328f404-88c3-5e0c-b24e-d16497eace45
STIX ID: report--c328f404-88c3-5e0c-b24e-d16497eace45
Feed Name: Aqua Security Blog
Threat Score
This blog describes the risks posed by malicious Linux kernel modules (kernel rootkits), how attackers load modules from memory to evade filesystem-based detection, the heightened danger for containerized/cloud environments (host escape and cross-container compromise), and demonstrates how Tracee can detect and dump volatile kernel modules for forensic analysis; it also references TeamTNT and the Diamorphine rootkit and mentions Aqua CNDR detection capabilities.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
