LoFP LoFP / rare temporary workaround for library misconfiguration

Techniques

Sample rules

Code Injection by ld.so Preload

Description

Detects the ld.so preload persistence file. See man ld.so for more information.

Detection logic

condition: keywords
keywords:
- /etc/ld.so.preload