logo

Ghosts in /proc: Manipulation and Timeline Corruption

ID: fb8b2012-a7e3-5ffa-a65c-2390b493f037

STIX ID: report--fb8b2012-a7e3-5ffa-a65c-2390b493f037

Feed Name: Group-IB Blog

Threat Score
55/100

Date Published: 2025-11-05

Date Updated: 2026-04-28

...
...

This blog demonstrates a technique for adversaries with elevated privileges to manipulate the Linux /proc pseudo-filesystem—by bind-mounting altered copies of /proc/<pid> entries—to falsify cmdline values and the starttime field in stat, allowing malicious processes to be disguised and timeline data to be corrupted; it includes a lab walkthrough and detection/mitigation guidance (monitor mount activity, cross-validate /proc data with kernel/remote telemetry, enforce least privilege, enable kernel integrity controls, and forward immutable audits).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.