Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Create Rule to detect Linux Process Code Injection #1

Merged
merged 1 commit into from
Nov 25, 2023

Commits on Nov 25, 2023

  1. Create Rule to detect Process Injection

    This commit adds a new experimental rule that attempts to detect process injection by utilizing the dd command to inject malicious code in the process memory under /proc/mem
    example provided in this project https://github.com/AonCyberLabs/Cexigua/blob/master/overwrite.sh
    skaynum committed Nov 25, 2023
    Configuration menu
    Copy the full SHA
    024315f View commit details
    Browse the repository at this point in the history