Microsoft has launched a rootkit detection service for Linux.

Microsoft introduced new free online service Freta, aimed at ensuring the verification of Linux environment images for rootkits, hidden processes, malware, and suspicious activity, such as intercepting system calls and using LD_PRELOAD to substitute library functions. The service requires uploading a system image snapshot to an external Microsoft server and is focused on checking the contents of virtual environments.

The output generates report, reflecting the state of system tables, kernel modules, network connections, debugging functions, and processes, which can be used in forensic analysis of breach consequences. It supports the analysis of over 4000 Linux kernel variations. Centralized remote configuration of a group of standard internet kiosks is possible with configuration loading over the network. Due to its small size, by default, the distribution is loaded entirely into RAM, which significantly increases performance. uploading snapshots of virtual environments in VMRS (Hyper-V checkpoint) and CORE (VMware snapshot) formats, as well as dumps of the operating system's memory state created using tools AVML and LiME. The service code is written in Rust.

Microsoft has launched a rootkit detection service for Linux.

Source: opennet.ru

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster