1200kmSECURITY RESEARCH
Loading interactive filters…

1200KM / detection

T1055.014 VDSO Hijacking — Detection Rules

Detection workspace for T1055.014 VDSO Hijacking: 0 Sigma sources, 0 Atlas concepts and 0 anomaly models. No live detection validation.

Source-backed rule directory

No reviewed association in this snapshot.

Atlas deterministic concepts

No exact concept selected.

Anomaly models

No exact Atlas model in this snapshot.

ATT&CK analytic guidance

DET0448 Detection Strategy for VDSO Hijacking on Linux

AN1241 Analytic 1241

Detects the redirection of syscall execution flow via modification of VDSO code stubs or GOT entries to load and execute a malicious shared object through mmap and ptrace.

Connected ecosystem references

Linked tags

Simulation, tools and telemetry

T1055.014 simulation workspace

No reviewed association in this snapshot.

Existing anomaly research

Original publication snapshot · Anomaly Detection Atlas

Pinned research references. No browser attack runner, live simulation result or validated detector is asserted. Source mappings and validation limits are preserved. ATT&CK / Atomic provenance · Detection provenance.