Detection:
* https://github.com/pandaadir05/ghost - patterns in the void, what is that ghostly malware
* https://github.com/openbsm/openbsm - the original UNIX auditd
Development:
* https://github.com/simonvetter/modbus - MODBUS in Go
Data:
* […]
Detection:
* https://github.com/pandaadir05/ghost - patterns in the void, what is that ghostly malware
* https://github.com/openbsm/openbsm - the original UNIX auditd
Development:
* https://github.com/simonvetter/modbus - MODBUS in Go
Data:
* […]
#tetragon #linux #cloud #native #информационная #безопасность #аудит #безопасности #kubernetes #auditd #kprobes
Origin | Interest | Match
#tetragon #linux #cloud #native #информационная #безопасность #аудит #безопасности #kubernetes #auditd #kprobes
Origin | Interest | Match
Lab drill: practice STIG hardening + auditd logs.
Search “IT security technician (DoD)” or “Endpoint security support.”
Lab drill: practice STIG hardening + auditd logs.
Search “IT security technician (DoD)” or “Endpoint security support.”
[Original post on social.linux.pizza]
[Original post on social.linux.pizza]
Interest | Match | Feed
Interest | Match | Feed
Origin | Interest | Match
excalibursheath.com/article/2025...
#Linux #SysAdmin
excalibursheath.com/article/2025...
#Linux #SysAdmin
#cybersecurity #tryhackme #questions-answers #linux-logging-for-soc #tryhackme-walkthrough
Origin | […]
#cybersecurity #tryhackme #questions-answers #linux-logging-for-soc #tryhackme-walkthrough
Origin | […]
blog.badsectorlabs.com/last-week-in...
blog.badsectorlabs.com/last-week-in...
• Root cause: Missing bounds check in process_client_hello()
• Exploit primitives: Arbitrary write + ASLR bypass via mmap grooming
• Detection: auditd rules for memfd_create syscalls Read more: 👉 tinyurl.com/3dp8x6ys
• Root cause: Missing bounds check in process_client_hello()
• Exploit primitives: Arbitrary write + ASLR bypass via mmap grooming
• Detection: auditd rules for memfd_create syscalls Read more: 👉 tinyurl.com/3dp8x6ys
Interest | Match | Feed
#wazuh #siem #open #source #cybersecurity #безопасность
Origin | Interest | Match
#wazuh #siem #open #source #cybersecurity #безопасность
Origin | Interest | Match
Interest | Match | Feed
#linux-security #technology #linux #audit #blue-team
Origin | Interest | Match
#linux-security #technology #linux #audit #blue-team
Origin | Interest | Match
Here an implant appears to be running from /usr/sbin/auditd but it's actually 'fileless'.
No '(deleted)', no ':memfd', no '/dev/shm', no ptrace, no LD_PRELOAD. Just stealth.
(6/7)
Here an implant appears to be running from /usr/sbin/auditd but it's actually 'fileless'.
No '(deleted)', no ':memfd', no '/dev/shm', no ptrace, no LD_PRELOAD. Just stealth.
(6/7)
#auditd #linux #безопасность #логирование #алерты
Origin | Interest | Match
#auditd #linux #безопасность #логирование #алерты
Origin | Interest | Match
#open-source #tech #automation #linux #technology
Origin | Interest | Match
#open-source #tech #automation #linux #technology
Origin | Interest | Match
Interest | Match | Feed
#tech #technology #linux #automation #open-source
Origin | Interest | Match
#tech #technology #linux #automation #open-source
Origin | Interest | Match