If you've been following Linux security, you know that eBPF is a double-edged sword. It's incredible for observability and networking, but it's also the new favorite playground for Linux rootkits. Most open-source security rules try to catch eBPF malware when it loads into the kernel (usually by watching bpftool **or the **bpf() syscall). But I... Weiterlesen
Intelligence View
I wrote a new Elastic detection rule to catch eBPF rootkits compiling on-host 🛡️
If you've been following Linux security, you know that eBPF is a double-edged sword. It's incredible for observability and networking, but it's also the new favorite playground for Linux rootkits. Most open-source security…
SOCIAL SHARE CARD GENERATOR