ZeroHour
Elastic Security Labspublished ()ingested Ruben Groenewoud

Linux Detection Engineering - Fileless Execution

infoResearchimportance 30
AI summary · glm-5.3-flash

Elastic Security Labs reproduces five Linux fileless execution patterns, including memfd_create staging and in-memory kernel module loads, and maps each to Elastic Defend rules.

Elastic Security Labs reproduced five Linux fileless execution patterns using its FENIX tooling: memfd_create staging, interpreter one-liners, deleted binaries, and in-memory kernel module loads. Each pattern is mapped to the Elastic Defend detection rules that catch it. The post is part of the team's ongoing Linux detection engineering series.

  • Five fileless execution patterns reproduced: memfd_create, interpreter one-liners, deleted binaries, in-memory kernel modules
  • Each pattern mapped to the corresponding Elastic Defend detection rules
  • Part of Elastic's ongoing Linux detection engineering series
Full article

We reproduced five Linux fileless execution patterns with FENIX, including memfd_create staging, interpreter one-liners, deleted binaries, and in-memory kernel module loads, then mapped each to the Elastic Defend rules that catch it.

This source does not provide full text. Read it at elastic.co.