{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","feed_url":"https://feed.craftedsignal.io/tags/tmpfs/feed.json","home_page_url":"https://feed.craftedsignal.io/","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":[],"_cs_severities":["medium"],"_cs_tags":["linux","post-exploitation","persistence","tmpfs"],"_cs_type":"advisory","_cs_vendors":[],"content_html":"\u003cp\u003eSecurity analysts have identified an increase in threat actors utilizing Linux shared memory directories, specifically /dev/shm/ and /run/shm/, to execute malicious binaries. These directories are backed by tmpfs, meaning they exist entirely in virtual memory and lack persistent storage on the physical disk. By staging and executing malware from these locations, attackers can maintain a footprint on high-uptime servers while effectively bypassing traditional disk-based forensic investigations. This activity is particularly concerning when performed by the root user, as it often signals the establishment of system backdoors or the final stages of privilege escalation. Monitoring for execution from these paths is a critical component of identifying stealthy post-exploitation activity on Linux endpoints.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows threat actors to maintain persistent, fileless backdoors on Linux infrastructure. Because these files do not persist on disk, detecting them requires real-time monitoring of process execution telemetry. Failure to detect this activity can lead to long-term unauthorized access, data exfiltration, and lateral movement within the environment without leaving traditional file-system artifacts for incident responders to analyze.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eDeploy the Sigma rules provided in this brief to monitor for process execution originating from /dev/shm/ and /run/shm/ by the root user.\u003c/li\u003e\n\u003cli\u003eEnable Sysmon for Linux (EventID 1) or equivalent EDR telemetry to capture process path and command-line execution data.\u003c/li\u003e\n\u003cli\u003eConfigure SIEM alerts to filter out legitimate applications that utilize these directories for transient inter-process communication; establish a baseline of known-good software behavior to minimize false positives.\u003c/li\u003e\n\u003cli\u003eIncorporate these detection points into incident response playbooks for Linux post-exploitation and privilege escalation hunts.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-07T15:15:19Z","date_published":"2026-08-07T15:15:19Z","id":"https://feed.craftedsignal.io/briefs/2026-08-linux-shm-execution/","summary":"Detection of root-level execution of binaries from volatile shared memory directories (/dev/shm/ and /run/shm/) used by threat actors for fileless persistence and forensic evasion.","title":"Detection of Linux Binary Execution from Shared Memory Directories","url":"https://feed.craftedsignal.io/briefs/2026-08-linux-shm-execution/"}],"language":"en","title":"CraftedSignal Threat Feed - Tmpfs","version":"https://jsonfeed.org/version/1.1"}