3 ms·
kernel state maps vs event buffering is an interesting choice. We've been seeing more in-memory malware in our CI/CD pipelines lately that never touches disk or
by belikebakar 2y ago
kernel state maps vs event buffering is an interesting choice. We've been seeing more in-memory malware in our CI/CD pipelines lately that never touches disk or network - any thoughts on extending this to userspace memory introspection?
- rafaeldavidtin 2y agoTake a look at https://jibril.garnet.ai/readme/theory-behind https://jibril.garnet.ai/readme/theory-behind so you have a better understanding what we are doing. As long as there is 'a resource' and 'an action', we can track it. Full memory (file-backed or not) introspection is tricky due to performance reasons (like checksumming files, picking entire content being read/write to pages, etc). Still, we would be able to do if we wanted (specially considering we can add uprobes on-demand for binaries being executed). Hope that helps.