Back to Browse

Linux Kernel-Mode rootkits: detecting hooked syscalls with Tracee.

481 views
Apr 25, 2024
0:46

Linux kernel-mode rootkits: detecting hooked syscalls with Tracee Tracee is a Runtime Security and Forensics tool that uses eBPF technology, it is very good for capturing and analyzing events that occur in the system and also detecting suspicious behavior patterns, how your system and applications are behaving. With tracee you can have detailed visibility into syscalls and other operations that are performed in the system. Tracee Project https://github.com/aquasecurity/tracee #tracee #linux #syscall #hook #kernel #rootkit #detect #forensics #ebpf

Download

0 formats

No download links available.

Linux Kernel-Mode rootkits: detecting hooked syscalls with Tracee. | NatokHD