timb-machine / timb-machine/linux-malware
[Intel]: https://sandflysecurity.com/blog/detecting-linux-binary-file-poisoning/
Open
@timb-machine is already working on this.
Since Jul 14, 2023.
confirmed
- Dominant language
- HTML
- Stars
- 1.2k
- Forks
- 95
- PR merge metrics
- No merged PRs in 30d
Description
Area
Defensive techniques
Parent threat
Execution, Persistence, Privilege Escalation, Defense Evasion
Finding
https://sandflysecurity.com/blog/detecting-linux-binary-file-poisoning/
Industry reference
attack:T1574:Hijack Execution Flow
attack:T1204:User Execution
attack:T1218:System Binary Proxy Execution
attack:T1036.003:Rename System Utilities
Malware reference
No response
Actor reference
No response
Component
Linux, AIX, Solaris, HP-UX
Scenario
No response
Contributor guide
No contributing guide indexed for this repository
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
Assessment
This issue has not been assessed yet.