Follow

cyberpress.org/linux-rootkit-a
Linux rootkit targets Elastic trusted_pids path Research on the Singularity Linux rootkit shows a loader can abuse Elastic Defend’s trusted_pids eBPF map to suppress module_load telemetry during malicious kernel module insertion. Testing cited Elastic Defend 9.5.2 on Ubuntu 6.8.0-138, where the BPF program exits early if the loading process is marked trusted, preventing module metadata collection and event creation.

· · vexo · 0 · 0 · 0
Sign in to participate in the conversation
Merovingian Club

A club for red-pilled exiles.