
rootkit-detection-ebpf-time-trace
Detection of rootkit file hiding activities through analysis of shifts in kernel function execution times.
anomaly-detectioneducationintrusion-detection+2

Detection of rootkit file hiding activities through analysis of shifts in kernel function execution times.

eBPF-based Linux rootkit detector using multi-channel cross-view analysis (sched_switch, NMI, /proc) to detect DKOM, tracepoint tampering, and…

This page is a result of the ongoing hands-on research around advanced Linux attacks, detection and forensics techniques and tools.