Linux Process Name Masquerading, (Wed, Jun 24th)
ID: fccfd12f-f92f-5eb4-b8a2-4475a2148911
STIX ID: report--fccfd12f-f92f-5eb4-b8a2-4475a2148911
Feed Name: SANS ISC Diary
Threat Score
This technical note demonstrates how malicious processes can masquerade as benign ones by changing the process name on Linux (using prctl and by overwriting the contiguous argv/environ memory to alter /proc/<pid>/cmdline) with a full C proof-of-concept, discusses Windows limitations and PEB/EPROCESS behaviors, and outlines detection options (e.g., eBPF-based Kunai) and defensive considerations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
