This website uses cookies to ensure you get the best experience.
Got it!
Register
|
Login
Menu
Home
Sigma Rules
Splunk Rules
Explore Rules
Analytic Stories
MITRE ATT&CK
Overview
Matrix
Techniques
Groups
Software
Campaigns
Search
About
ASLR Disabled Via Sysctl or Direct Syscall - Linux
Original Source:
[Sigma source]
Title:
ASLR Disabled Via Sysctl or Direct Syscall - Linux
Status:
experimental
Description:
Detects actions that disable Address Space Layout Randomization (ASLR) in Linux, including: - Use of the `personality` syscall with the ADDR_NO_RANDOMIZE flag (0x0040000) - Modification of the /proc/sys/kernel/randomize_va_space file - Execution of the `sysctl` command to set `kernel.randomize_va_space=0` Disabling ASLR is often used by attackers during exploit development or to bypass memory protection mechanisms. A successful use of these methods can reduce the effectiveness of ASLR and make memory corruption attacks more reliable.
References:
-https://github.com/CheraghiMilad/bypass-Neo23x0-auditd-config/blob/f1c478a37911a5447d5ffcd580f22b167bf3df14/personality-syscall/README.md
-https://man7.org/linux/man-pages/man2/personality.2.html
-https://manual.cs50.io/2/personality
-https://linux-audit.com/linux-aslr-and-kernelrandomize_va_space-setting/
Author:
Milad Cheraghi
Date:
2025-05-26
modified:
2025-12-05
Tags:
-'attack.privilege-escalation'
-'attack.stealth'
-'attack.defense-impairment'
-'attack.t1685'
-'attack.t1055.009'
Logsource:
product: linux
service: auditd
Detection:
selection_syscall:
type
:
'SYSCALL'
SYSCALL
:
'personality'
a0
:
'40000'
selection_sysctl:
type
:
'EXECVE'
a0
:
'sysctl'
a1
:
'-w'
a2
:
'kernel.randomize_va_space=0'
condition
:
1 of selection_*
Falsepositives:
-Debugging or legitimate software testing
Level:
high