THREAT OPS › Threat News › Linux Detection Engineering - Fileless Execution
Linux Detection Engineering - Fileless Execution
<p>Fileless execution on Linux has moved from niche tradecraft into real-world intrusion chains. By executing payloads from memory or anonymous file descriptors, attackers can reduce on-disk artifacts and weaken controls that rely heavily on file inspection.</p><p>In <a href="https://www.elastic.co/security-labs/illuminating-voidlink">our own analysis of VoidLink</a>, we observed how fileless exec
MITRE ATT&CK techniques
Indicators of compromise
- 5779b9f935dd181ddf4047d9c0a404a90da94ed2sha1
- 73692c8be828f1071e1cb628c6ae0d0205f386c9sha1
- a9208f465f486bf87dd614c463eb5e790d559a52sha1
- 3d4f9fe12471e805616c3f41b1aca6efca990f8bsha1
- https://socket.dev/blog/pypi-package-impersonates-sympy-to-deliver-cryptomining-malwareurl
- https://www.trendmicro.com/en_us/research/26/e/quasar-linux-qlnx-a-silent-foothold-in-the-software-supply-chain.htmlurl
- https://man7.org/linux/man-pages/man2/memfd_create.2.htmlurl
- https://magisterquis.github.io/2018/03/31/in-memory-only-elf-execution.htmlurl
- https://mohitdabas.in/blog/linux-maldev-fileless-execution-memfd-create/url
- https://blog.jrdioca.com/offensive%20security/offensive%20security%20-%20evasion/red%20teaming/apt%20emulation/2026/01/04/PerlyShells/url
- https://isc.sans.edu/diary/32384url
- https://<url>/nytOFXqs.rburl
- https://redcanary.com/blog/linux-security/detection-engineer-guide-to-linux/url
- static-www.elastic.codomain