Process Injection: Proc Memory T1055.009

Tactics: Stealth, Privilege Escalation

Adversaries may inject malicious code into processes via the /proc filesystem in order to evade process-based defenses as well as possibly elevate privileges. Proc memory injection is a method of executing arbitrary code in the address space of a separate live process.

Events covered

3 catalog events are tagged with this technique by at least one rule.

ProviderEventTitle
Linux-AuditdEvent ID 1300SYSCALL
Linux-AuditdEvent ID 1309EXECVE
Sysmon-for-LinuxEvent ID 1Process Create

Authoring guide

These 15 rules share fields, values, and exclusions.

Fields filtered most (16 distinct)

These fields appear most often in rule filters.

FieldRulesHowSample values
event.type12eq 11, ne 1start, deletion
EventType11eq 11exec, memfd_create, load_module, connection_attempted
Image9starts_with 6, regex_match 3, wildcard 2, ends_with 1?memfd:, memfd:, ./*, /boot/*, /dev/shm/*
process.args5regex_match 3, eq 2, starts_with 2, wildcard 1/proc/(self|[0-9]{1,7})/fd/[0-9]{1,7}, -c, -e, -r
process_name4starts_with 3, wildcard 3, ends_with 1, in 1*.bin, *.js, *.lua, ., .bin
ParentImage3starts_with 2, is_not_null 1?memfd:, memfd:
process.args_count2le 22
CommandLine1contains 1/mem, /proc/, of=
SYSCALL1eq 1personality
TargetFilename1wildcard 1/boot/*, /dev/shm/*, /home/*/*
a01eq 140000, sysctl
a11eq 1-w
a21eq 1kernel.randomize_va_space=0
parent_process_name1in 1bash, busybox, csh
process.interactive1eq 1true

Top indicator values (191 distinct)

These values appear most often in rule predicates.

FieldKindValueRules (here)Corpus reach
event.typeeq
start
111087
EventTypeeq
exec
7579
EventTypeeq
memfd_create
67
EventTypeeq
load_module
27
Imagestarts_with
?memfd:
67
Imagestarts_with
memfd:
56
Imageregex_match
/proc/(self|[0-9]{1,7})/fd/[0-9]{1,7}
35
process.argsregex_match
/proc/(self|[0-9]{1,7})/fd/[0-9]{1,7}
33
process_namewildcard
lua*
334
process_namewildcard
perl*
337
process_namewildcard
php*
341
process_namewildcard
python*
371
process_namewildcard
ruby*
335
Imagewildcard
./*
217
Imagewildcard
/boot/*
221
Imagewildcard
/dev/shm/*
230
Imagewildcard
/home/*/*
223
Imagewildcard
/lost+found/*
210
Imagewildcard
/proc/*
210
Imagewildcard
/root/*
213
Imagewildcard
/run/user/*
210
Imagewildcard
/sys/*
210
Imagewildcard
/tmp/*
234
Imagewildcard
/var/mail/*
210
Imagewildcard
/var/run/user/*
210
Imagewildcard
/var/tmp/*
232
Imagewildcard
/var/www/*
214
Imagewildcard
?memfd:*
23
Imagewildcard
memfd:*
23
ParentImagestarts_with
?memfd:
23

Exclusions (316 distinct)

These values appear most often in top-level exclusions.

FieldKindValueRules excluding
CommandLineeq
buildah-chroot-runtime
3
Imageeq
memfd:spawn_worker_trampoline
3
Imageeq
/memfd: (deleted)
2
CurrentDirectoryeq
/run/nordlayer
2
Imagein
/usr/bin/fusermount
2
Imagein
/usr/bin/fusermount3
2
Imagein
/usr/sbin/logrotate
2
Imagein
memfd:buildah-chroot-exec
2
Imagein
memfd:buildah-chroot-runtime
2
Imagein
memfd:lxc-attach
2
Imagein
memfd:runc_cloned:/proc/self/exe
2
Imagewildcard
/app/bin/evolution.bin
2
Imagewildcard
/home/*/.local/share/claude/versions/*
2
Imagewildcard
/usr/bin/qgis.bin
2
ParentCommandLinein
/dev/fd/4 -config /etc/nordlayer/config.hcl
2

Rules under this technique

These vendors publish rules tagged with this technique.

Platform: Linux

Domain: Endpoint

Sigma 2 rules

Elastic 13 rules