guardicore / labs_campaigns

355 stars 106 forks source link

NFS file systems unlink() renames #10

Open pellucida opened 4 years ago

pellucida commented 4 years ago

When searching for "deleted" missing the case where the executable was run and deleted on an NFS volume. eg /proc/114028/exe -> /people/tiffin/.nfs0000000004b40e9f00093dd8