10000 pkg/ebpf: add derived events for ld SO symbols collision (rebase) by rafaeldtinoco · Pull Request #2740 · aquasecurity/tracee · GitHub
[go: up one dir, main page]
More Web Proxy on the site http://driver.im/
Skip to content

pkg/ebpf: add derived events for ld SO symbols collision (rebase) #2740

New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Merged
merged 2 commits into from
Feb 17, 2023
Merged

pkg/ebpf: add derived events for ld SO symbols collision (rebase) #2740

merged 2 commits into from
Feb 17, 2023

Conversation

rafaeldtinoco
Copy link
Contributor

This is #2053 rebased and with a minor fix.

AlonZivony and others added 2 commits February 17, 2023 10:21
Generate a derived event in the case that a shared object loaded
to a process export the same symbols as a loaded shared object.
This helps to detect cases of hooking shared library functions.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants
0