1 min read
Basic Linux Malware Process Forensics for Incident Responders
Publication date: 30 September 2019
1 min read
Sandfly Security - Agentless Linux EDR and Incident Response Updated on September 29, 2026
The commands used in this video are referenced below.
Setup a benign process to run in a way that mimics common Linux malware by masquerading what it is. In this case we use the simple system sleep command but rename it as cron before running it:
export PATH=.:$PATH cd /tmp
cp /bin/sleep cron
cron 3600 &The export PATH statement makes the command in the immediate directory run without needing to add a “./” in front of it. Then we cd to /tmp which is an extremely common location for malicious activity on Linux. We next copy the system /bin/sleep command to something named cron under /tmp. Finally, we run our new “cron” command with 3600 as the argument. Since this is really a sleep command it will simply wait for 3600 seconds (an hour) before exiting.
The above mimics malware in the following ways:
Commands used to view process start-up basics (strings or cat versions):
strings /proc/<PID>/comm cat /proc/<PID>/commDisplay the full command line used with the process:
strings /proc/<PID>/cmdline cat /proc/<PID>/cmdlineView a link where the binary is located on the filesystem:
ls -al /proc/<PID>/exeThis is an ongoing series of basic command line forensics for Linux. Please subscribe to see more.
1 min read
Publication date: 30 September 2019
1 min read
Publication Date: 08 July 2020
1 min read
Publication Date: 30 March 2020