timb-machine / linux-malware

Tracking interesting Linux (and UNIX) malware. Send PRs
The Unlicense
1.11k stars 90 forks source link

[Intel]: https://blog.trailofbits.com/2021/11/09/all-your-tracing-are-belong-to-bpf/ #747

Open timb-machine opened 1 year ago

timb-machine commented 1 year ago

Area

Defensive techniques

Parent threat

Persistence, Defense Evasion

Finding

https://blog.trailofbits.com/2021/11/09/all-your-tracing-are-belong-to-bpf/

Industry reference

uses:eBPF attack:T1620:Reflective Code Loading

Malware reference

No response

Actor reference

No response

Component

Linux

Scenario

No response