初探Linux内核eBPF之恶意程序行为监控 | CTF导航
Tags
attack-pattern: Data
Common Information
Type Value
UUID 2f21afa8-1f6b-4757-8c0e-8d6957be2c68
Fingerprint 6e3486c92a5bb608
Analysis status DONE
Considered CTI value -2
Text language
Published Nov. 4, 2024, midnight
Added to db Nov. 4, 2024, 9:14 a.m.
Last updated Nov. 17, 2024, 7:44 p.m.
Headline 初探Linux内核eBPF之恶意程序行为监控
Title 初探Linux内核eBPF之恶意程序行为监控 | CTF导航
Detected Hints/Tags/Attributes 15/1/14
Source URLs
RSS Feed
Details Id Enabled Feed title Url Added to db
Details 426 CTF导航 https://www.ctfiot.com/feed 2024-08-30 22:08
Attributes
Details Type #Events CTI Value
Details Domain 4127
github.com
Details Domain 32
golang.org
Details Domain 1
objs.bpfmaps.events
Details Domain 1
rd.read
Details Domain 1
errors.is
Details Domain 1
binary.read
Details Domain 1
event.pid
Details Domain 1
event.host
Details File 1
objs.sys
Details File 1
record.raw
Details Github username 2
cilium
Details IPv4 1441
127.0.0.1
Details Url 1
https://github.com/cilium/ebpf/tree/main/examples
Details Url 4
http://127.0.0.1:8888