Tag
medium
advisory
Detection of Linux Persistence via Systemd Generators
1 rule 2 TTPsThis detection identifies potential persistence on Linux systems by monitoring for unauthorized file creation or modification within the /lib/systemd/system-generators/ directory, which executes during the boot sequence.
systemd
persistence
linux
1r
2t
medium
advisory
Leveraging Linux Cgroups for Threat Detection and Investigation
2 rulesThis brief outlines how Linux cgroups, a kernel feature for resource management, can be repurposed to provide valuable telemetry for detecting malicious processes, particularly in systemd, Docker, and Kubernetes environments, aiding in investigations of server compromises.
Red Hat Enterprise Linux +5
linux
cgroups
container
kubernetes
docker
systemd
threat-detection
2r