Process Injection: Proc Memory T1055.009
Tactics: Stealth, Privilege Escalation
Adversaries may inject malicious code into processes via the /proc filesystem in order to evade process-based defenses as well as possibly elevate privileges. Proc memory injection is a method of executing arbitrary code in the address space of a separate live process.
Events covered
3 catalog events are tagged with this technique by at least one rule.
| Provider | Event | Title |
|---|---|---|
| Linux-Auditd | Event ID 1300 | SYSCALL |
| Linux-Auditd | Event ID 1309 | EXECVE |
| Sysmon-for-Linux | Event ID 1 | Process Create |
Authoring guide
These 15 rules share fields, values, and exclusions.
Fields filtered most (16 distinct)
These fields appear most often in rule filters.
Top indicator values (191 distinct)
These values appear most often in rule predicates.
Exclusions (316 distinct)
These values appear most often in top-level exclusions.
Rules under this technique
These vendors publish rules tagged with this technique.
Platform: Linux
Domain: Endpoint
Sigma 2 rules
- ASLR Disabled Via Sysctl or Direct Syscall - Linux
- Potential Linux Process Code Injection Via DD Utility
Elastic 13 rules
- Egress Network Connection from Memory File Descriptor
- Execution of Memory File Descriptor via Suspicious Process
- File Creation or Modification via (Memory) File Descriptor
- Loadable Kernel Module Load via Forked Memory File Descriptor
- Memory File Descriptor Child Process Execution
- Memory File Descriptor Execution from Suspicious Process
- Memory File Descriptor Process Execution
- Network Activity via (Memory) File Descriptor
- Potential Fileless Execution Sequence
- Potential Fileless Execution via Memory File Descriptor by LoLBin
- Potential Fileless Execution via Memory File Descriptor from Interpreter
- Potential Loadable Kernel Module Load via Memory File Descriptor
- Potential Memory File Descriptor Process Execution