3 ms·
I don't know reverse engineering. But, I guess the ultimate solution would be running a custom OS to fake ptrace results in the kernel level?
by harryfyx 3y ago
I don't know reverse engineering. But, I guess the ultimate solution would be running a custom OS to fake ptrace results in the kernel level?
- scandinavian 3y agoYou can just use LD_PRELOAD to load your own version of ptrace. Not as stealthy though.
- pizzapim 3y agoAnother way is to load a eBPF program or kernel module for this purpose.