Process Injection: Ptrace System Calls T1055.008

Tactics: Stealth, Privilege Escalation

Adversaries may inject malicious code into processes via ptrace (process trace) system calls in order to evade process-based defenses as well as possibly elevate privileges. Ptrace system call injection is a method of executing arbitrary code in the address space of a separate live process.

Authoring guide

These 4 rules share fields, values, and exclusions.

Fields filtered most (10 distinct)

These fields appear most often in rule filters.

FieldRulesHowSample values
EventType4eq 3, in 1exec, ProcessRollup2, connection_attempted, exec_event, uid_change
event.type4eq 4start, change
host.os.type4eq 4
process_name4eq 4, is_not_null 2gdb, sudo
process.thread.capabilities.effective2eq 2cap_sys_ptrace
process.thread.capabilities.permitted2eq 2cap_sys_ptrace
user.id2eq 2, ne 20
process.args1in 1, ne 1--pid, -p, 1
process.group.id1eq 1, ne 10
process.user.id1eq 1, ne 10

Top indicator values (24 distinct)

These values appear most often in rule predicates.

FieldKindValueRules (here)Corpus reach
event.typeeq
start
41087
event.typeeq
change
195
process_nameeq
gdb
46
process_nameeq
sudo
115
EventTypeeq
exec
3579
EventTypeeq
connection_attempted
175
EventTypeeq
uid_change
119
process.thread.capabilities.effectiveeq
cap_sys_ptrace
22
process.thread.capabilities.permittedeq
cap_sys_ptrace
22
user.ideq
0
228
user.idne
0
228
EventTypein
ProcessRollup2
1118
EventTypein
exec
1206
EventTypein
exec_event
1150
EventTypein
executed
198
EventTypein
process_started
183
EventTypein
start
1168
process.argsin
--pid
13
process.argsin
-p
14
process.argsne
1
1
process.group.ideq
0
110
process.group.idne
0
1
process.user.ideq
0
110
process.user.idne
0
1

Rules under this technique

These vendors publish rules tagged with this technique.

Platform: Linux

Domain: Endpoint

Elastic 4 rules