logo

Hiding in plain sight: Techniques and defenses against `/proc` filesystem manipulation in Linux

ID: c6e98867-f959-53b7-a5bd-903f1bf422e2

STIX ID: report--c6e98867-f959-53b7-a5bd-903f1bf422e2

Feed Name: Group-IB Blog

Threat Score
50/100

Date Published: 2024-08-26

Date Updated: 2026-04-28

...
...

This report explains how attackers can hide processes on Linux systems by bind-mounting an empty directory over /proc, demonstrates that direct removal of /proc entries is prevented but bind-mounting can mask processes from standard tools (ps, ss), and recommends mitigations including enabling SELinux/AppArmor and routinely checking the mount table to detect such evasions.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.