Linux Level 5 260 points

Linux-eBPF Rootkit. Unmasking a Hidden Process

Mission

This challenge safely recreates eBPF-rootkit investigation as offline evidence analysis. Without loading eBPF or touching the host kernel, inspect the supplied bpftool snapshot and map dump to recover the hidden file path.

#linux#ebpf#rootkit

Clear it in 3 steps

Not started
  1. Start the environment

  2. Investigate the target

  3. Submit the flag