AN1631
Analytic 1631
Linux
Monitoring adversary access to sensitive process memory via the /proc filesystem to extract credential material, often involving multi-step access to /proc/[pid]/mem or /proc/[pid]/maps combined with privilege escalation or credential scraping binaries.
auditd:SYSCALL
open, read
auditd:SYSCALL
write
auditd:SYSCALL
ptrace or process_vm_readv
linux:Sysmon
EventCode=1
[AccessedFilePath]
Monitored paths such as /proc/[pid]/mem or /proc/[pid]/maps may need to be scoped based on environment
[ProcessName]
Command-line or binary names associated with credential scraping tools may vary
[UserContext]
Elevated user or unexpected user context accessing other process memory may indicate malicious activity
[TimeWindow]
Correlating memory access with process creation or ptrace activity within a specific time range