Cross-source coverage

T1055.009 / ATT&CK

Process Injection: Proc Memory

15 rules across 2 sources.

From MITRE ATT&CK 19.2

Adversaries may inject malicious code into processes via the /proc filesystem in order to evade process-based defenses as well as possibly elevate privileges. Proc memory injection is a method of executing arbitrary code in the address space of a separate live process.

Proc memory injection involves enumerating the memory of a process via the /proc filesystem (/proc/[pid]) then crafting a return-oriented programming (ROP) payload with available gadgets/instructions. Each running process has its own directory, which includes memory mappings. Proc memory injection is commonly performed by overwriting the target processes’ stack using memory mappings provided by the /proc filesystem. This information can be used to enumerate offsets (including the stack) and gadgets (or instructions within the program that can be used to build a malicious payload) otherwise hidden by process memory protections such as address space layout randomization (ASLR). Once enumerated, the target processes’ memory map within /proc/[pid]/maps can be overwritten using dd.

Other techniques such as Dynamic Linker Hijacking may be used to populate a target process with more available gadgets. Similar to Process Hollowing, proc memory injection may target child processes (such as a backgrounded copy of sleep).

Running code in the context of another process may allow access to the process's memory, system/network resources, and possibly elevated privileges. Execution via proc memory injection may also evade detection from security products since the execution is masked under a legitimate process.

Platforms
Linux
Telemetry
auditd:SYSCALLlinux:osquery

How MITRE says to detect it DET0541

Detection Strategy for /proc Memory Injection on Linux

Linux Analytic 1494

Detects adversary behavior where a process enumerates and modifies another process's memory using /proc/[pid]/maps and /proc/[pid]/mem files. This includes identifying gadgets via memory mappings and overwriting process memory via low-level file modification or dd usage.

  • auditd:SYSCALL open/write to /proc/*/mem or /proc/*/maps
  • auditd:SYSCALL execve of dd or sed targeting /proc/*/mem
  • linux:osquery /proc/*/maps access

elastic/protections-artifacts

13 rules
Detection Severity Format
Egress Network Connection from Memory File Descriptor Undefined Elastic TOML
Execution of Memory File Descriptor via Suspicious Process Undefined Elastic TOML
File Creation or Modification via (Memory) File Descriptor Undefined Elastic TOML
Loadable Kernel Module Load via Forked Memory File Descriptor Undefined Elastic TOML
Memory File Descriptor Child Process Execution Undefined Elastic TOML
Memory File Descriptor Execution from Suspicious Process Undefined Elastic TOML
Memory File Descriptor Process Execution Undefined Elastic TOML
Network Activity via (Memory) File Descriptor Undefined Elastic TOML
Potential Fileless Execution Sequence Undefined Elastic TOML
Potential Fileless Execution via Memory File Descriptor by LoLBin Undefined Elastic TOML

+ 3 more from elastic/protections-artifacts → showing the 10 highest-severity

SigmaHQ/sigma

2 rules
Detection Severity Format
ASLR Disabled Via Sysctl or Direct Syscall - Linux High Sigma
Potential Linux Process Code Injection Via DD Utility Medium Sigma

Detection rules belong to the projects that publish them and remain under their own licenses. This site indexes and links to them; it claims no rights in them.