criblio / appscope

Gain observability into any Linux command or application with no code modification
https://appscope.dev
Apache License 2.0
264 stars 32 forks source link

Content: Investigate security use cases #1052

Closed jrcheli closed 1 year ago

jrcheli commented 2 years ago

Pick an exploit, and see what AppScope can do to report security events that could help someone determine that they've been infected.

Ebury seems like an interesting choice because of its sophistication... https://malpedia.caad.fkie.fraunhofer.de/details/elf.ebury

Mitre Att&ck seems like a really great way of looking at exploits from a perspective where AppScope appears to have the potential to make a real difference... https://attack.mitre.org/

seanvaleo commented 1 year ago

We demo'd this with marketing and security teams internally and decided not to proceed with this at this time.