RGROSEC
open-menucloseme
Home
About me
github linkedin
  • Copy Fail and DirtyFrag: Linux Page Cache Bugs in the Wild

    calendar May 9, 2026 · 1 min read · Detection Engineering Linux Elastic  ·
    Share on: twitter facebook linkedin copy
    Copy Fail and DirtyFrag: Linux Page Cache Bugs in the Wild

    At Elastic Security Labs, together with Eric Forte and Samir Bousseaden, we analyzed the Linux kernel privilege escalation vulnerabilities Copy Fail (CVE-2026-31431), Copy Fail 2, and DirtyFrag. These issues exploit subtle page cache corruption bugs to create reliable paths to root access, using legitimate kernel …


    Read More
  • Hooked on Linux: Rootkit Detection Engineering

    calendar Apr 2, 2026 · 1 min read · Malware Analysis Detection Engineering Linux Elastic  ·
    Share on: twitter facebook linkedin copy
    Hooked on Linux: Rootkit Detection Engineering

    In the second part of our two-part Linux rootkit series at Elastic Security Labs, Remco Sprooten and I turn from theory to detection engineering. We begin by demonstrating why static detection is often unreliable against Linux rootkits—even trivial modifications like stripping binaries or appending a single null byte …


    Read More
  • Linux & Cloud Detection Engineering - TeamPCP Container Attack Scenario

    calendar Mar 20, 2026 · 1 min read · Detection Engineering Linux Containers Elastic  ·
    Share on: twitter facebook linkedin copy
    Linux & Cloud Detection Engineering - TeamPCP Container Attack Scenario

    At Elastic Security Labs, I published a real-world walkthrough of TeamPCP's multi-stage container compromise, demonstrating how Elastic's Defend for Containers (D4C) surfaces runtime signals across each stage of the attack chain. Rather than analyzing isolated techniques in abstraction, we follow the attack as it …


    Read More
  • Linux & Cloud Detection Engineering - Getting Started with Defend for Containers (D4C)

    calendar Mar 19, 2026 · 1 min read · Detection Engineering Linux Containers Elastic  ·
    Share on: twitter facebook linkedin copy
    Linux & Cloud Detection Engineering - Getting Started with Defend for Containers (D4C)

    At Elastic Security Labs, I published a comprehensive walkthrough of Elastic's Defend for Containers (D4C) integration, covering Kubernetes-based deployment, BPF-enriched runtime telemetry analysis, and the practical application of policy-driven security controls for containerized Linux environments. Defend for …


    Read More
  • Linux Detection Engineering - The Grand Finale on Linux Persistence Mechanisms

    calendar Feb 25, 2025 · 1 min read · Detection Engineering Hunting Linux Persistence Elastic  ·
    Share on: twitter facebook linkedin copy
    Linux Detection Engineering - The Grand Finale on Linux Persistence Mechanisms

    In the fifth and final part of the Linux Persistence Detection Engineering series, we bring the journey to its grand finale by exploring some of the most obscure, creative, and complex persistence mechanisms. Building on the foundational concepts covered in previous publications, this final installment focuses on …


    Read More
  • Linux Detection Engineering - Approaching the Summit on Persistence Mechanisms

    calendar Feb 11, 2025 · 1 min read · Detection Engineering Hunting Linux Persistence Elastic  ·
    Share on: twitter facebook linkedin copy
    Linux Detection Engineering -  Approaching the Summit on Persistence Mechanisms

    In the fourth part of the Linux Persistence Detection Engineering series, I continue exploring advanced Linux persistence techniques, expanding on the foundation set in previous publications. This latest installment delves into additional creative and complex methods adversaries use to maintain persistence on Linux …


    Read More
  • Linux Detection Engineering - A Continuation on Persistence Mechanisms

    calendar Jan 27, 2025 · 1 min read · Detection Engineering Hunting Linux Persistence Elastic  ·
    Share on: twitter facebook linkedin copy
    Linux Detection Engineering -  A Continuation on Persistence Mechanisms

    In the third part of the Linux Persistence Detection Engineering series, I continue exploring advanced Linux persistence techniques, expanding on the foundation set in previous publications. This latest installment dives into more creative and complex persistence methods, providing security researchers and defenders …


    Read More
  • Securing the edge: Harnessing Falco's power with Elastic Security for cloud workload protection

    calendar Nov 15, 2024 · 1 min read · Detection Engineering Linux Elastic  ·
    Share on: twitter facebook linkedin copy
    Securing the edge: Harnessing Falco's power with Elastic Security for cloud workload protection

    At Elastic, we recognize the critical need for securing containerized applications in Kubernetes and cloud environments. To enhance runtime security, we’ve integrated Falco—an open-source cloud-native security tool—directly with Elastic Security. Falco leverages Linux kernel events and plugins to detect abnormal …


    Read More
  • Cups Overflow: When your printer spills more than Ink

    calendar Sep 28, 2024 · 1 min read · CVE Detection Engineering Linux Elastic  ·
    Share on: twitter facebook linkedin copy
    Cups Overflow: When your printer spills more than Ink

    At Elastic Security Labs, we analyzed a critical set of vulnerabilities in the CUPS printing system, disclosed by security researcher Simone Margaritelli (@evilsocket) on September 26, 2024. These flaws, affecting CUPS versions ≤ 2.0.1, enable unauthenticated remote attackers to achieve remote code execution (RCE) via …


    Read More
  • Linux Detection Engineering - A sequel on persistence mechanisms

    calendar Aug 29, 2024 · 1 min read · Detection Engineering Hunting Linux Persistence Elastic  ·
    Share on: twitter facebook linkedin copy
    Linux Detection Engineering - A sequel on persistence mechanisms

    In this second part of the Linux Persistence Detection Engineering series, I explore the world of more advanced Linux persistence techniques. This part builds upon the knowledge obtained from the previous persistence blog dubbed "Linux Detection Engineering - A Primer on Persistence Mechanisms". This sequel …


    Read More
    • ««
    • «
    • 1
    • 2
    • »
    • »»

Ruben Groenewoud

Security researcher at Elastic, writing about detection engineering, Linux security, and offensive security.
Read More

Featured Posts

  • Copy Fail and DirtyFrag: Linux Page Cache Bugs in the Wild
  • Hooked on Linux: Rootkit Detection Engineering
  • Illuminating VoidLink: Technical analysis of the VoidLink rootkit framework
  • Linux & Cloud Detection Engineering - TeamPCP Container Attack Scenario
  • Linux & Cloud Detection Engineering - Getting Started with Defend for Containers (D4C)
  • Hooked on Linux: Rootkit Taxonomy, Hooking Techniques and Tradecraft
  • Outlaw Linux Malware: Persistent, Unsophisticated, and Surprisingly Effective
  • Linux Detection Engineering - The Grand Finale on Linux Persistence Mechanisms

Recent Posts

  • Copy Fail and DirtyFrag: Linux Page Cache Bugs in the Wild
  • Hooked on Linux: Rootkit Detection Engineering
  • Illuminating VoidLink: Technical analysis of the VoidLink rootkit framework
  • Linux & Cloud Detection Engineering - TeamPCP Container Attack Scenario
  • Linux & Cloud Detection Engineering - Getting Started with Defend for Containers (D4C)
  • Hooked on Linux: Rootkit Taxonomy, Hooking Techniques and Tradecraft
  • Outlaw Linux Malware: Persistent, Unsophisticated, and Surprisingly Effective
  • Linux Detection Engineering - The Grand Finale on Linux Persistence Mechanisms

Categories

ELASTIC 18 DETECTION ENGINEERING 12 LINUX 12 MALWARE ANALYSIS 7 WALKTHROUGHS 7 PERSISTENCE 5 WEB APPLICATION HACKING 4 BINARY EXPLOITATION 2 PRIVILEGE ESCALATION 2 CVE 1

Tags

LINUX 25 ELASTIC 18 DETECTION ENGINEERING 12 HACK THE BOX 7 MALWARE ANALYSIS 7 HUNTING 5 PERSISTENCE 5 OWASP 4 WEBAPP 4 WINDOWS 4 BUFFER OVERFLOW 2 CONTAINERS 2 PRIVILEGE ESCALATION 2 ROOTKIT 2
All Tags
AUDITD1 BUFFER OVERFLOW2 CONTAINERS2 CVE1 DETECTION ENGINEERING12 ELASTIC18 HACK THE BOX7 HUNTING5 LINUX25 MALWARE ANALYSIS7 OWASP4 PERSISTENCE5 PRIVILEGE ESCALATION2 ROOTKIT2 WEBAPP4 WINDOWS4
[A~Z][0~9]
RGROSEC

Copyright  RGROSEC. All Rights Reserved

to-top