Cross-source coverage
T1055.009 / ATT&CK
Process Injection: Proc Memory
15 rules across 2 sources.
From MITRE ATT&CK 19.2
Adversaries may inject malicious code into processes via the /proc filesystem in order to evade process-based defenses as well as possibly elevate privileges. Proc memory injection is a method of executing arbitrary code in the address space of a separate live process.
Proc memory injection involves enumerating the memory of a process via the /proc filesystem (/proc/[pid]) then crafting a return-oriented programming (ROP) payload with available gadgets/instructions. Each running process has its own directory, which includes memory mappings. Proc memory injection is commonly performed by overwriting the target processes’ stack using memory mappings provided by the /proc filesystem. This information can be used to enumerate offsets (including the stack) and gadgets (or instructions within the program that can be used to build a malicious payload) otherwise hidden by process memory protections such as address space layout randomization (ASLR). Once enumerated, the target processes’ memory map within /proc/[pid]/maps can be overwritten using dd.
Other techniques such as Dynamic Linker Hijacking may be used to populate a target process with more available gadgets. Similar to Process Hollowing, proc memory injection may target child processes (such as a backgrounded copy of sleep).
Running code in the context of another process may allow access to the process's memory, system/network resources, and possibly elevated privileges. Execution via proc memory injection may also evade detection from security products since the execution is masked under a legitimate process.
- Tactics
- Stealth · Privilege Escalation
- Platforms
- Linux
- Telemetry
-
auditd:SYSCALLlinux:osquery
How MITRE says to detect it DET0541
Detection Strategy for /proc Memory Injection on Linux
Linux Analytic 1494
Detects adversary behavior where a process enumerates and modifies another process's memory using /proc/[pid]/maps and /proc/[pid]/mem files. This includes identifying gadgets via memory mappings and overwriting process memory via low-level file modification or dd usage.
auditd:SYSCALLopen/write to /proc/*/mem or /proc/*/mapsauditd:SYSCALLexecve of dd or sed targeting /proc/*/memlinux:osquery/proc/*/maps access
elastic/protections-artifacts
13 rules| Detection | Severity | Format |
|---|---|---|
| Egress Network Connection from Memory File Descriptor | Undefined | Elastic TOML |
| Execution of Memory File Descriptor via Suspicious Process | Undefined | Elastic TOML |
| File Creation or Modification via (Memory) File Descriptor | Undefined | Elastic TOML |
| Loadable Kernel Module Load via Forked Memory File Descriptor | Undefined | Elastic TOML |
| Memory File Descriptor Child Process Execution | Undefined | Elastic TOML |
| Memory File Descriptor Execution from Suspicious Process | Undefined | Elastic TOML |
| Memory File Descriptor Process Execution | Undefined | Elastic TOML |
| Network Activity via (Memory) File Descriptor | Undefined | Elastic TOML |
| Potential Fileless Execution Sequence | Undefined | Elastic TOML |
| Potential Fileless Execution via Memory File Descriptor by LoLBin | Undefined | Elastic TOML |
+ 3 more from elastic/protections-artifacts → showing the 10 highest-severity
SigmaHQ/sigma
2 rules| Detection | Severity | Format |
|---|---|---|
| ASLR Disabled Via Sysctl or Direct Syscall - Linux | High | Sigma |
| Potential Linux Process Code Injection Via DD Utility | Medium | Sigma |