menu
techminis

A naukri.com initiative

google-web-stories
source image

Securityaffairs

2w

read

68

img
dot

Image Credit: Securityaffairs

PoC rootkit Curing evades traditional Linux detection systems

  • Researchers created a PoC rootkit named Curing that uses Linux's io_uring feature to evade traditional system call monitoring.
  • Curing is a proof-of-concept rootkit that utilizes io_uring for performing tasks without syscalls, making it undetectable by security tools.
  • io_uring is a Linux API for asynchronous I/O that bypasses system calls, making syscall-based security tools ineffective.
  • Many Linux EDRs are unable to monitor io_uring-based activity, posing a risk to current Linux security solutions.

Read Full Article

like

4 Likes

For uninterrupted reading, download the app