Process Injection: Ptrace System Calls T1055.008
Tactics: Stealth, Privilege Escalation
Adversaries may inject malicious code into processes via ptrace (process trace) system calls in order to evade process-based defenses as well as possibly elevate privileges. Ptrace system call injection is a method of executing arbitrary code in the address space of a separate live process.
Authoring guide
These 4 rules share fields, values, and exclusions.
Fields filtered most (10 distinct)
These fields appear most often in rule filters.
Top indicator values (24 distinct)
These values appear most often in rule predicates.
Rules under this technique
These vendors publish rules tagged with this technique.
Platform: Linux
Domain: Endpoint