THREATOPS
THREAT OPSThreat News › Linux Detection Engineering - Fileless Execution

Linux Detection Engineering - Fileless Execution

medelastic_securityPublished 2026-09-01

<p>Fileless execution on Linux has moved from niche tradecraft into real-world intrusion chains. By executing payloads from memory or anonymous file descriptors, attackers can reduce on-disk artifacts and weaken controls that rely heavily on file inspection.</p><p>In <a href="https://www.elastic.co/security-labs/illuminating-voidlink">our own analysis of VoidLink</a>, we observed how fileless exec

MITRE ATT&CK techniques

Indicators of compromise

Original source: https://www.elastic.co/security-labs/threat-command/memfd-create-linux-fileless-execution