Detecting eBPF Malware with Tracee
ID: c68e1022-8c0e-5bc6-b0b2-e03712c518d3
STIX ID: report--c68e1022-8c0e-5bc6-b0b2-e03712c518d3
Feed Name: Aqua Security Blog
Threat Score
### Executive Summary This report examines malicious uses of eBPF, focusing on the pamspy malware which uses eBPF uprobes to hook pam_get_authtok in libpam.so and capture cleartext credentials; it details how eBPF programs are loaded and attached via Perf events (tracepoints, kprobes, uprobes, and their return variants) and describes how Aqua Tracee correlates eBPF and Perf event data to detect such malicious instrumentation.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
