timb-machine / linux-malware

Tracking interesting Linux (and UNIX) malware. Send PRs
The Unlicense
1.11k stars 90 forks source link

[Intel]: https://github.com/hardenedvault/ved-ebpf #737

Open timb-machine opened 1 year ago

timb-machine commented 1 year ago

Area

Defensive tools

Parent threat

Execution, Privilege Escalation, Defense Evasion

Finding

https://github.com/hardenedvault/ved-ebpf

Industry reference

attack:T1574:Hijack Execution Flow attack:T1548.001:Setuid and Setgid attack:T1620:Reflective Code Loading attack:T1068:Exploitation for Privilege Escalation uses:eBPF

Malware reference

No response

Actor reference

No response

Component

Linux

Scenario

No response