Hiding in plain sight: Techniques and defenses against `/proc` filesystem manipulation in Linux
ID: c6e98867-f959-53b7-a5bd-903f1bf422e2
STIX ID: report--c6e98867-f959-53b7-a5bd-903f1bf422e2
Feed Name: Group-IB Blog
Threat Score
This report explains how attackers can hide processes on Linux systems by bind-mounting an empty directory over /proc, demonstrates that direct removal of /proc entries is prevented but bind-mounting can mask processes from standard tools (ps, ss), and recommends mitigations including enabling SELinux/AppArmor and routinely checking the mount table to detect such evasions.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
