Microsoft new free online service , at ensuring the verification of Linux environment images for rootkits, hidden processes, malware, and suspicious activity, such as intercepting system calls and using LD_PRELOAD to substitute library functions. The service requires uploading a system image snapshot to an external Microsoft server and is focused on checking the contents of virtual environments.
The output generates , reflecting the state of system tables, kernel modules, network connections, debugging functions, and processes, which can be used in forensic analysis of breach consequences. It supports the analysis of over 4000 Linux kernel variations. uploading snapshots of virtual environments in VMRS (Hyper-V checkpoint) and CORE (VMware snapshot) formats, as well as dumps of the operating system's memory state created using tools and . The service code is written in Rust.
Source: opennet.ru
