Falco informational stable other

PTRACE anti-debug attempt

Detect usage of the PTRACE system call with the PTRACE_TRACEME argument, indicating a program actively attempting to avoid debuggers attaching to the process. This behavior is typically indicative of malware activity. Read more about PTRACE in the "PTRACE attached to process" rule.

View Source

Detection Logic

evt.type=ptrace and evt.arg.request contains PTRACE_TRACEME and proc_name_exists

Field Validations

Loading…

Comments (0)

Loading comments...