RGROSEC
open-menucloseme
Home
About me
github linkedin
  • Linux & Cloud Detection Engineering - TeamPCP Container Attack Scenario

    calendar Mar 20, 2026 · 1 min read · Detection Engineering Linux Containers Elastic  ·
    Share on: twitter facebook linkedin copy
    Linux & Cloud Detection Engineering - TeamPCP Container Attack Scenario

    At Elastic Security Labs, I published a real-world walkthrough of TeamPCP's multi-stage container compromise, demonstrating how Elastic's Defend for Containers (D4C) surfaces runtime signals across each stage of the attack chain. Rather than analyzing isolated techniques in abstraction, we follow the attack as it …


    Read More
  • Linux & Cloud Detection Engineering - Getting Started with Defend for Containers (D4C)

    calendar Mar 19, 2026 · 1 min read · Detection Engineering Linux Containers Elastic  ·
    Share on: twitter facebook linkedin copy
    Linux & Cloud Detection Engineering - Getting Started with Defend for Containers (D4C)

    At Elastic Security Labs, I published a comprehensive walkthrough of Elastic's Defend for Containers (D4C) integration, covering Kubernetes-based deployment, BPF-enriched runtime telemetry analysis, and the practical application of policy-driven security controls for containerized Linux environments. Defend for …


    Read More

Ruben Groenewoud

Security researcher at Elastic, writing about detection engineering, Linux security, and offensive security.
Read More

Featured Posts

  • Copy Fail and DirtyFrag: Linux Page Cache Bugs in the Wild
  • Hooked on Linux: Rootkit Detection Engineering
  • Illuminating VoidLink: Technical analysis of the VoidLink rootkit framework
  • Linux & Cloud Detection Engineering - TeamPCP Container Attack Scenario
  • Linux & Cloud Detection Engineering - Getting Started with Defend for Containers (D4C)
  • Hooked on Linux: Rootkit Taxonomy, Hooking Techniques and Tradecraft
  • Outlaw Linux Malware: Persistent, Unsophisticated, and Surprisingly Effective
  • Linux Detection Engineering - The Grand Finale on Linux Persistence Mechanisms

Recent Posts

  • Copy Fail and DirtyFrag: Linux Page Cache Bugs in the Wild
  • Hooked on Linux: Rootkit Detection Engineering
  • Illuminating VoidLink: Technical analysis of the VoidLink rootkit framework
  • Linux & Cloud Detection Engineering - TeamPCP Container Attack Scenario
  • Linux & Cloud Detection Engineering - Getting Started with Defend for Containers (D4C)
  • Hooked on Linux: Rootkit Taxonomy, Hooking Techniques and Tradecraft
  • Outlaw Linux Malware: Persistent, Unsophisticated, and Surprisingly Effective
  • Linux Detection Engineering - The Grand Finale on Linux Persistence Mechanisms

Categories

ELASTIC 18 DETECTION ENGINEERING 12 LINUX 12 MALWARE ANALYSIS 7 WALKTHROUGHS 7 PERSISTENCE 5 WEB APPLICATION HACKING 4 BINARY EXPLOITATION 2 PRIVILEGE ESCALATION 2 CVE 1

Tags

LINUX 25 ELASTIC 18 DETECTION ENGINEERING 12 HACK THE BOX 7 MALWARE ANALYSIS 7 HUNTING 5 PERSISTENCE 5 OWASP 4 WEBAPP 4 WINDOWS 4 BUFFER OVERFLOW 2 CONTAINERS 2 PRIVILEGE ESCALATION 2 ROOTKIT 2
All Tags
AUDITD1 BUFFER OVERFLOW2 CONTAINERS2 CVE1 DETECTION ENGINEERING12 ELASTIC18 HACK THE BOX7 HUNTING5 LINUX25 MALWARE ANALYSIS7 OWASP4 PERSISTENCE5 PRIVILEGE ESCALATION2 ROOTKIT2 WEBAPP4 WINDOWS4
[A~Z][0~9]
RGROSEC

Copyright  RGROSEC. All Rights Reserved

to-top