LoFP LoFP / legitimate applications may use shared memory directories for temporary file storage or inter-process communication. verify any flagged activity against known software behavior and filter accordingly.

Techniques

Sample rules

Linux Binary Executed from Shared Memory Directory

Description

The following analytic identifies the execution of a binary by root from Linux shared memory directories (/dev/shm/ and /run/shm/). Threat actors place executables in these directories to persist on high-uptime servers as system backdoors. Both /dev/shm and /run/shm are tmpfs-backed directories that exist only in virtual memory with no persistent storage, making them attractive for staging fileless or semi-fileless malware while avoiding disk forensics.

Detection logic


| tstats `security_content_summariesonly`
  count min(_time) as firstTime
        max(_time) as lastTime

from datamodel=Endpoint.Processes where

Processes.process_path IN (
    "/dev/shm/*",
    "/run/shm/*"
)
Processes.user=root

by Processes.process Processes.process_path Processes.process_name Processes.user
   Processes.user_id Processes.process_hash Processes.parent_process_name
   Processes.parent_process_path Processes.parent_process Processes.parent_process_guid
   Processes.parent_process_id Processes.process_guid Processes.process_id
   Processes.vendor_product Processes.action Processes.dest
   Processes.process_current_directory Processes.process_integrity_level
   Processes.original_file_name


| `drop_dm_object_name(Processes)`

| `security_content_ctime(firstTime)`

| `security_content_ctime(lastTime)`

| `linux_binary_executed_from_shared_memory_directory_filter`