A Linux process running with an immutable binary is almost never legitimate.
Attackers set the immutable flag so you can't delete their payload mid-incident. It’s a huge red flag that a system is compromised.
ap1.hubs.ly/H01kJD10
#Linux #eBPF
Agentless Linux security. We post threat hunting, DFIR and hardening for people running Linux in production. No agents, no kernel modules.



