1200KM / detection
T1055.009 Proc Memory — Detection Rules
Detection workspace for T1055.009 Proc Memory: 2 Sigma sources, 0 Atlas concepts and 0 anomaly models. No live detection validation.
Source-backed rule directory
- ASLR Disabled Via Sysctl or Direct Syscall - Linux · experimental · high · {"product":"linux","service":"auditd"}
- Potential Linux Process Code Injection Via DD Utility · test · medium · {"product":"linux","category":"process_creation"}
Atlas deterministic concepts
No exact concept selected.
Anomaly models
No exact Atlas model in this snapshot.
ATT&CK analytic guidance
DET0541 Detection Strategy for /proc Memory Injection on Linux
AN1494 Analytic 1494
Detects adversary behavior where a process enumerates and modifies another process's memory using /proc/[pid]/maps and /proc/[pid]/mem files. This includes identifying gadgets via memory mappings and overwriting process memory via low-level file modification or dd usage.
Connected ecosystem references
Linked tags
Simulation, tools and telemetry
T1055.009 simulation workspace
No reviewed association in this snapshot.
Existing anomaly research
Pinned research references. No browser attack runner, live simulation result or validated detector is asserted. Source mappings and validation limits are preserved. ATT&CK / Atomic provenance · Detection provenance.