- PyCQA/bandit (Python SAST) plugin: logging_config_insecure_listen
- CIS Benchmark for Linux: 1.5.3 - Ensure ptrace_scope is restricted
- VirusTotal YARA: Identified a
vulnerabilitybug that allows log injection which can be leveraged to evade detection - Improvement to osquery pack Behavioral_Reverse_Shell
- Zammad (Ruby code review)
- bpfdoorpoc: PoC for bpfdoor rootkit's eBPF technique and effective detection
- python-logging.config-exploit: PoC for Python's security consideration "logging: Logging configuration uses eval()"
- termspy: PoC terminal keylogger using ptrace
- ptrace_code_injection: PoC for injecting code into existing process with ptrace
- chkproc.py: PoC script to detect processes hidden by rootkits
- vscode_trusted_rce: PoC for code execution from loading a trusted project in VSCode