Linux Threat Hunting: ‘Syslogk’ a kernel rootkit found under development in the wild

Introduction Rootkits are dangerous pieces of malware. Once in place, they are usually really hard to detect. Their code is typically more challenging to write than other malware, so developers resort to code reuse from open source projects. As rootkits are very interesting to analyze, we are always looking out for these kinds of samples … Continue reading Linux Threat Hunting: ‘Syslogk’ a kernel rootkit found under development in the wild