Falco informational stable other
PTRACE anti-debug attempt
Detect usage of the PTRACE system call with the PTRACE_TRACEME argument, indicating a program actively attempting to avoid debuggers attaching to the process. This behavior is typically indicative of malware activity. Read more about PTRACE in the "PTRACE attached to process" rule.
Detection Logic
evt.type=ptrace and evt.arg.request contains PTRACE_TRACEME and proc_name_exists Field Validations
Loading…
Comments (0)
Loading comments...