Deleted Process Binary Attack on Linux
Linux恶意软件常删除磁盘二进制文件以规避传统安全工具检测。Sandfly的无代理LinuxEDR可识别此类威胁,并通过命令行取证分析恢复运行进程进行深入研究。 2024-12-19 20:8:44 Author: sandflysecurity.com(查看原文) 阅读量:1 收藏

Sandfly Blog

Malware on Linux will often delete the on-disk binary to evade detection with traditional anti-virus and file integrity monitoring tools. In this video we will discuss the threat and how to find it with Sandfly's agentless Linux EDR. We'll then show you how to investigate it with command line forensics and recover the running process binary for analysis.

Sandfly is able to find this and many other types of Linux attacks without deploying any endpoint agents. Get your free license today or contact us for more information.



文章来源: https://sandflysecurity.com/blog/deleted-process-binary-attack-on-linux
如有侵权请联系:admin#unsafe.sh