elastic
low
eql
Deprecated - Potential Process Injection via LD_PRELOAD Environment Variable
This rule detects the execution of a process where the LD_PRELOAD environment variable is set. LD_PRELOAD can be used to
inject a shared library into a binary at or prior to execution. A threat actor may do this in order to load a malicious
shared library for the purposes of persistence, privilege escalation, and defense evasion. This activity is not common
and will potentially indicate malicious or suspicious behavior.