logo

Detecting eBPF Malware with Tracee

ID: c68e1022-8c0e-5bc6-b0b2-e03712c518d3

STIX ID: report--c68e1022-8c0e-5bc6-b0b2-e03712c518d3

Feed Name: Aqua Security Blog

Threat Score
70/100

Date Published: 2023-07-19

Date Updated: 2026-04-26

...
...

### Executive Summary This report examines malicious uses of eBPF, focusing on the pamspy malware which uses eBPF uprobes to hook pam_get_authtok in libpam.so and capture cleartext credentials; it details how eBPF programs are loaded and attached via Perf events (tracepoints, kprobes, uprobes, and their return variants) and describes how Aqua Tracee correlates eBPF and Perf event data to detect such malicious instrumentation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.