featured post

How to APT EP. 4: : The Verifier Forgot It Was a Pointer: Commuted-Add Type Confusion and Container Escapes

An analysis of a Linux kernel BPF verifier type confusion vulnerability caused by premature early returns in commuted arithmetic. It demonstrates how an attacker with CAP_BPF can abuse untrusted pointer state divergence to leak kernel heap addresses and cross container boundaries.

Linux Kernel eBPF BPF Verifier Type Confusion Container Escape Maldev Rootkit KASLR
Aug 10, 2026  ·  13 min read  ·  18 views
read →
Kernel Exploitation How to APT EP. 4: : The Verifier Forgot It Was a Pointer: Commuted-Add Type Confusion and Container Escapes Aug 10, 2026
Offensive Security, Linux Kernel Security, Cyber Security Research How to APT EP. 3: Owning Thread Execution with sched_ext Hashmaps Aug 8, 2026
eBPF, kernel How to APT EP.2: Lying to the whole netns through BPF_PROG_TYPE_FLOW_DISSECTOR Aug 2, 2026
eBPF Security How to APT EP.1: Bypassing XDP and TC: Stealthy Connection Interception via BPF SK_LOOKUP Jul 30, 2026
Linux, Kernel, shellcode Cacheghost: Executing code from the kernel page cache Jul 30, 2026
8posts
0papers
92topics
3278total views
Offensive Security, Linux Kernel Security, Cyber Security Research ·ebpf

How to APT EP. 3: Owning Thread Execution with sched_ext Hashmaps

sched_ext lets custom BPF programs replace the core Linux CPU dispatcher. But when the entire attack surface of a rootkit is a 16-byte write to an already-trusted BPF hashmap, no EDR hook-monitor will ever see it coming. Here is how a custom scheduler becomes the ultimate process inventory and targeted starvation weapon.

Aug 8, 2026 15 min 58 views
eBPF, kernel ·eBPF

How to APT EP.2: Lying to the whole netns through BPF_PROG_TYPE_FLOW_DISSECTOR

Flowdiss explores how BPF_PROG_TYPE_FLOW_DISSECTOR can be abused to forge the Linux kernel's notion of packet flow identity without modifying packet contents. By manipulating the flow_keys used to derive skb->hash, a privileged eBPF program can influence downstream consumers such as RPS, GRO, ECMP, and other eBPF programs that rely on the cached flow hash. The article presents a proof of concept, validates its effects and limitations, and demonstrates how a separate BPF LSM program can conceal the attack from standard bpftool enumeration, illustrating both an underexplored attack surface and the limits of relying on user-space BPF tooling on a compromised system.

Aug 2, 2026 22 min 1,234 views
eBPF Security ·ebpf

How to APT EP.1: Bypassing XDP and TC: Stealthy Connection Interception via BPF SK_LOOKUP

While most offensive eBPF techniques rely on XDP or TC to intercept raw network packets, Linux 5.6+ introduced BPF_PROG_TYPE_SK_LOOKUP, a hook operating at the socket dispatch layer. By attaching a 28-line BPF program directly to a network namespace, an attacker can silently redirect incoming TCP SYN requests to a backdoor socket without modifying packets, recalculating checksums, altering iptables rules, or leaving wire-level artifacts. This post breaks down how the technique works, common implementation traps, why it evades conventional EDR checks, and how defenders can audit for it.

Jul 30, 2026 16 min 579 views
Linux, Kernel, shellcode ·linux-kernel

Cacheghost: Executing code from the kernel page cache

A file-backed executable mapping where the page content diverges from the backing file.

Jul 30, 2026 5 min 228 views
Kernel ·bpf

I Spent a Week Fuzzing the BPF Verifier's New Circular Number System

I spent the better part of a week reverse-engineering Meta's ~3500 line refactoring of the BPF verifier's bounds tracking, the "circular number" (or cnum) rework that landed in Linux 7.0. I built a fuzzer, ran a quarter million random tests, traced through the linked register propagation by hand, disassembled my running kernel's vmlinux to check for backports, and generally went deeper into `kernel/bpf/verifier.c` than any sane person should.

Jul 29, 2026 4 min 144 views