How to APT EP. 4: : The Verifier Forgot It Was a Pointer: Commuted-Add Type Confusion and Container Escapes
An analysis of a Linux kernel BPF verifier type confusion vulnerability caused by premature early returns in commuted arithmetic. It demonstrates how an attacker with CAP_BPF can abuse untrusted pointer state divergence to leak kernel heap addresses and cross container boundaries.
How to APT EP. 3: Owning Thread Execution with sched_ext Hashmaps
sched_ext lets custom BPF programs replace the core Linux CPU dispatcher. But when the entire attack surface of a rootkit is a 16-byte write to an already-trusted BPF hashmap, no EDR hook-monitor will ever see it coming. Here is how a custom scheduler becomes the ultimate process inventory and targeted starvation weapon.
How to APT EP.2: Lying to the whole netns through BPF_PROG_TYPE_FLOW_DISSECTOR
Flowdiss explores how BPF_PROG_TYPE_FLOW_DISSECTOR can be abused to forge the Linux kernel's notion of packet flow identity without modifying packet contents. By manipulating the flow_keys used to derive skb->hash, a privileged eBPF program can influence downstream consumers such as RPS, GRO, ECMP, and other eBPF programs that rely on the cached flow hash. The article presents a proof of concept, validates its effects and limitations, and demonstrates how a separate BPF LSM program can conceal the attack from standard bpftool enumeration, illustrating both an underexplored attack surface and the limits of relying on user-space BPF tooling on a compromised system.
How to APT EP.1: Bypassing XDP and TC: Stealthy Connection Interception via BPF SK_LOOKUP
While most offensive eBPF techniques rely on XDP or TC to intercept raw network packets, Linux 5.6+ introduced BPF_PROG_TYPE_SK_LOOKUP, a hook operating at the socket dispatch layer. By attaching a 28-line BPF program directly to a network namespace, an attacker can silently redirect incoming TCP SYN requests to a backdoor socket without modifying packets, recalculating checksums, altering iptables rules, or leaving wire-level artifacts. This post breaks down how the technique works, common implementation traps, why it evades conventional EDR checks, and how defenders can audit for it.
Cacheghost: Executing code from the kernel page cache
A file-backed executable mapping where the page content diverges from the backing file.
