RGROSEC
open-menucloseme
Home
About me
github linkedin
  • Copy Fail and DirtyFrag: Linux Page Cache Bugs in the Wild

    calendar May 9, 2026 · 1 min read · Detection Engineering Linux Elastic  ·
    Share on: twitter facebook linkedin copy
    Copy Fail and DirtyFrag: Linux Page Cache Bugs in the Wild

    At Elastic Security Labs, together with Eric Forte and Samir Bousseaden, we analyzed the Linux kernel privilege escalation vulnerabilities Copy Fail (CVE-2026-31431), Copy Fail 2, and DirtyFrag. These issues exploit subtle page cache corruption bugs to create reliable paths to root access, using legitimate kernel …


    Read More
  • Hooked on Linux: Rootkit Detection Engineering

    calendar Apr 2, 2026 · 1 min read · Malware Analysis Detection Engineering Linux Elastic  ·
    Share on: twitter facebook linkedin copy
    Hooked on Linux: Rootkit Detection Engineering

    In the second part of our two-part Linux rootkit series at Elastic Security Labs, Remco Sprooten and I turn from theory to detection engineering. We begin by demonstrating why static detection is often unreliable against Linux rootkits—even trivial modifications like stripping binaries or appending a single null byte …


    Read More
  • Illuminating VoidLink: Technical analysis of the VoidLink rootkit framework

    calendar Mar 26, 2026 · 1 min read · Malware Analysis Linux Rootkit Elastic  ·
    Share on: twitter facebook linkedin copy
    Illuminating VoidLink: Technical analysis of the VoidLink rootkit framework

    At Elastic Security Labs, Remco Sprooten and I analyzed a data dump containing source code, compiled binaries, and deployment scripts for the kernel rootkit components of VoidLink—a cloud-native Linux malware framework first documented by Check Point Research. The dump revealed a multigenerational rootkit framework …


    Read More
  • Linux & Cloud Detection Engineering - TeamPCP Container Attack Scenario

    calendar Mar 20, 2026 · 1 min read · Detection Engineering Linux Containers Elastic  ·
    Share on: twitter facebook linkedin copy
    Linux & Cloud Detection Engineering - TeamPCP Container Attack Scenario

    At Elastic Security Labs, I published a real-world walkthrough of TeamPCP's multi-stage container compromise, demonstrating how Elastic's Defend for Containers (D4C) surfaces runtime signals across each stage of the attack chain. Rather than analyzing isolated techniques in abstraction, we follow the attack as it …


    Read More
  • Linux & Cloud Detection Engineering - Getting Started with Defend for Containers (D4C)

    calendar Mar 19, 2026 · 1 min read · Detection Engineering Linux Containers Elastic  ·
    Share on: twitter facebook linkedin copy
    Linux & Cloud Detection Engineering - Getting Started with Defend for Containers (D4C)

    At Elastic Security Labs, I published a comprehensive walkthrough of Elastic's Defend for Containers (D4C) integration, covering Kubernetes-based deployment, BPF-enriched runtime telemetry analysis, and the practical application of policy-driven security controls for containerized Linux environments. Defend for …


    Read More
  • Hooked on Linux: Rootkit Taxonomy, Hooking Techniques and Tradecraft

    calendar Mar 5, 2026 · 1 min read · Malware Analysis Linux Rootkit Elastic  ·
    Share on: twitter facebook linkedin copy
    Hooked on Linux: Rootkit Taxonomy, Hooking Techniques and Tradecraft

    In the first part of our two-part Linux rootkit series at Elastic Security Labs, Remco Sprooten and I explore the theory behind how rootkits work: their taxonomy, evolution, and the hooking techniques they use to subvert the kernel. We trace the progression from early userland shared object rootkits through LKM-based …


    Read More
  • Outlaw Linux Malware: Persistent, Unsophisticated, and Surprisingly Effective

    calendar Apr 1, 2025 · 1 min read · Malware Analysis Linux Elastic  ·
    Share on: twitter facebook linkedin copy
    Outlaw Linux Malware: Persistent, Unsophisticated, and Surprisingly Effective

    At Elastic Security Labs, Remco Sprooten and I analyzed OUTLAW, a persistent yet unsophisticated auto-propagating coinminer package that remains active across multiple versions despite lacking advanced evasion techniques. It leverages simple but impactful tactics such as SSH brute-forcing, SSH key and cron-based …


    Read More
  • Linux Detection Engineering - The Grand Finale on Linux Persistence Mechanisms

    calendar Feb 25, 2025 · 1 min read · Detection Engineering Hunting Linux Persistence Elastic  ·
    Share on: twitter facebook linkedin copy
    Linux Detection Engineering - The Grand Finale on Linux Persistence Mechanisms

    In the fifth and final part of the Linux Persistence Detection Engineering series, we bring the journey to its grand finale by exploring some of the most obscure, creative, and complex persistence mechanisms. Building on the foundational concepts covered in previous publications, this final installment focuses on …


    Read More
  • Linux Detection Engineering - Approaching the Summit on Persistence Mechanisms

    calendar Feb 11, 2025 · 1 min read · Detection Engineering Hunting Linux Persistence Elastic  ·
    Share on: twitter facebook linkedin copy
    Linux Detection Engineering -  Approaching the Summit on Persistence Mechanisms

    In the fourth part of the Linux Persistence Detection Engineering series, I continue exploring advanced Linux persistence techniques, expanding on the foundation set in previous publications. This latest installment delves into additional creative and complex methods adversaries use to maintain persistence on Linux …


    Read More
  • Linux Detection Engineering - A Continuation on Persistence Mechanisms

    calendar Jan 27, 2025 · 1 min read · Detection Engineering Hunting Linux Persistence Elastic  ·
    Share on: twitter facebook linkedin copy
    Linux Detection Engineering -  A Continuation on Persistence Mechanisms

    In the third part of the Linux Persistence Detection Engineering series, I continue exploring advanced Linux persistence techniques, expanding on the foundation set in previous publications. This latest installment dives into more creative and complex persistence methods, providing security researchers and defenders …


    Read More
    • ««
    • «
    • 1
    • 2
    • 3
    • »
    • »»

Ruben Groenewoud

Security researcher at Elastic, writing about detection engineering, Linux security, and offensive security.
Read More

Featured Posts

  • Copy Fail and DirtyFrag: Linux Page Cache Bugs in the Wild
  • Hooked on Linux: Rootkit Detection Engineering
  • Illuminating VoidLink: Technical analysis of the VoidLink rootkit framework
  • Linux & Cloud Detection Engineering - TeamPCP Container Attack Scenario
  • Linux & Cloud Detection Engineering - Getting Started with Defend for Containers (D4C)
  • Hooked on Linux: Rootkit Taxonomy, Hooking Techniques and Tradecraft
  • Outlaw Linux Malware: Persistent, Unsophisticated, and Surprisingly Effective
  • Linux Detection Engineering - The Grand Finale on Linux Persistence Mechanisms

Recent Posts

  • Copy Fail and DirtyFrag: Linux Page Cache Bugs in the Wild
  • Hooked on Linux: Rootkit Detection Engineering
  • Illuminating VoidLink: Technical analysis of the VoidLink rootkit framework
  • Linux & Cloud Detection Engineering - TeamPCP Container Attack Scenario
  • Linux & Cloud Detection Engineering - Getting Started with Defend for Containers (D4C)
  • Hooked on Linux: Rootkit Taxonomy, Hooking Techniques and Tradecraft
  • Outlaw Linux Malware: Persistent, Unsophisticated, and Surprisingly Effective
  • Linux Detection Engineering - The Grand Finale on Linux Persistence Mechanisms

Categories

ELASTIC 18 DETECTION ENGINEERING 12 LINUX 12 MALWARE ANALYSIS 7 WALKTHROUGHS 7 PERSISTENCE 5 WEB APPLICATION HACKING 4 BINARY EXPLOITATION 2 PRIVILEGE ESCALATION 2 CVE 1

Tags

LINUX 25 ELASTIC 18 DETECTION ENGINEERING 12 HACK THE BOX 7 MALWARE ANALYSIS 7 HUNTING 5 PERSISTENCE 5 OWASP 4 WEBAPP 4 WINDOWS 4 BUFFER OVERFLOW 2 CONTAINERS 2 PRIVILEGE ESCALATION 2 ROOTKIT 2
All Tags
AUDITD1 BUFFER OVERFLOW2 CONTAINERS2 CVE1 DETECTION ENGINEERING12 ELASTIC18 HACK THE BOX7 HUNTING5 LINUX25 MALWARE ANALYSIS7 OWASP4 PERSISTENCE5 PRIVILEGE ESCALATION2 ROOTKIT2 WEBAPP4 WINDOWS4
[A~Z][0~9]
RGROSEC

Copyright  RGROSEC. All Rights Reserved

to-top