Linux Immutable Malware Process Binary Attack
Linux系统中运行不可变二进制文件的进程通常是恶意软件。文章介绍此类攻击的检测方法及命令行取证工具。Sandfly无需端点代理即可检测多种Linux攻击,并提供免费许可。 2025-1-6 22:26:9 Author: sandflysecurity.com(查看原文) 阅读量:1 收藏

Sandfly Blog

06 January 2025

Videos

Processes running with an immutable binary are nearly always malware on Linux. Learn what this attack is, how to automatically detect it, and command line forensics you can use to investigate suspicious processes using this attack tactic.

Sandfly is able to find this and many other types of Linux attacks without deploying any endpoint agents. Get your free license today or contact us for more information.

Full transcript available here.



文章来源: https://sandflysecurity.com/blog/linux-immutable-malware-process-binary-attack
如有侵权请联系:admin#unsafe.sh