timb-machine / linux-malware

Tracking interesting Linux (and UNIX) malware. Send PRs
The Unlicense
1.11k stars 90 forks source link

[Intel]: https://code-white.com/blog/2023-08-blindsiding-auditd-for-fun-and-profit/ #739

Open timb-machine opened 1 year ago

timb-machine commented 1 year ago

Area

Malware PoCs

Parent threat

Defense Evasion

Finding

https://code-white.com/blog/2023-08-blindsiding-auditd-for-fun-and-profit/

Industry reference

attack:T1562.001:Disable or Modify Tools attack:T1562:Impair Defenses

Malware reference

https://github.com/timb-machine/linux-malware/issues/734 https://github.com/timb-machine/linux-malware/issues/740

Actor reference

No response

Component

Linux

Scenario

No response