[ Changelog / Updates ]
[ Changelog / Updates ]
Linux Attack, Detection and Forensics v2.1 - Hands-on Purple Teaming Playbook
Introduction
Introduction
Defensive/DFIR Tooling
Defensive/DFIR Tooling
Linux EDR Architecture
Linux EDR Architecture
Linux MITRE ATT&CK Matrix
Linux MITRE ATT&CK Matrix
Initial Access - TA0001
Initial Access - TA0001
Persistence - TA0003
Persistence - TA0003
Privilege Escalation - TA0004
Privilege Escalation - TA0004
Defense Evasion - TA0005
Defense Evasion - TA0005
Command and Control - TA0011
Command and Control - TA0011
Discovery - TA0007
Discovery - TA0007
Lateral Movement - TA0008
Lateral Movement - TA0008
Exfiltration - TA0010
Exfiltration - TA0010
Automated Attack Emulation Projects
Automated Attack Emulation Projects
Kubernetes
Kubernetes
Here you can find information about the provided updates, modifications, and new lab scenarios:
-
13.07.2026:
-
Host/Tetragon Custom Tracing Policies:
-
Host/Tetragon Runtime Security:
-
Custom eBPF C:
https://edu.defensive-security.com/p/courses/linux-attack-detection-and-live-forensics-v2-0/3350642-defensive-dfir-tooling/11862991-custom-ebpf-c [UPDATED => Prevent Ghostlock CVE-2026-43499 exploitation - live patch]
-
-
9.07.2026:
-
EDR-T6485 - Falco BPF Map Poisoning:
-
EDR-T6459 - Copy Fail - CVE-2026-31431 LPE:
https://edu.defensive-security.com/p/courses/linux-attack-detection-and-live-forensics-v2-0/3342719-privilege-escalation-ta0004/11807887-edr-t6459-copy-fail-cve-2026-31431-lpe [UPDATED => New Velociraptor artifact has been added - Linux.Detection.CopyFail.Exploitation]
-
Host/Falco Runtime Security:
https://edu.defensive-security.com/p/courses/linux-attack-detection-and-live-forensics-v2-0/3350642-defensive-dfir-tooling/10922528-host-falco-runtime-security [UPDATED => new ruleset added, Falco engine updated to v0.44]
-
-
8.07.2026:
-
O-EDR-T6468 - DirtyClone CVE-2026-43503:
-
K8S - EDR-T6105 - Apache HTTPD CVE-2021-41773:
-
K8S - EDR-T6464 - Tomcat Tribes CVE-2026-34486:
-
K8S - EDR-T6062 - Kafka CVE-2023-25194:
-
K8S - EDR-T6114 - ActiveMQ CVE-2023-46604:
-
K8S - EDR-T6467 - Flask SSTI:
-
K8S - EDR-T6355 - Langflow API CVE-2025-3248:
-
K8S - EDR-T6416 - React2shell - CVE-2025-55182:
-
K8S - EDR-T6113 - Spring CVE-2022-22963:
-
K8S - EDR-T6354 - Remote UAF+Heap Overflow:
-
-
6.07.2026:
-
Codex/Claude Code AI Integration:
-
-
30.06.2026:
-
Custom eBPF C:
https://edu.defensive-security.com/p/courses/linux-attack-detection-and-live-forensics-v2-0/3350642-defensive-dfir-tooling/11862991-custom-ebpf-c [Detect/prevent overwriting modprobe_path via physmap region + Detect/prevent overwriting modprobe_path via VA .data section + Detect/prevent overwriting core_pattern via VA .data section + physmap region]
-
-
29.06.2026:
-
Memory/Volatility3 Framework:
-
-
16.05.2026:
-
EDR-T6360 - UAF Dirty Page Table LPE:
https://edu.defensive-security.com/view/courses/linux-attack-detection-and-live-forensics-v2-0/3342719-privilege-escalation-ta0004/10910681-edr-t6360-uaf-dirty-page-table-lpe [UPDATED => Tetragon Prevention Policy added]
-
-
15.05.2026:
-
EDR-T6463 - pidfd_getfd + ptrace - Read root files:
-
-
14.05.2026:
-
EDR-T6459 - Copy Fail - CVE-2026-31431 LPE:
-
EDR-T6462 - Fragnesia LPE:
-
EDR-T6261 - Remote UAF Exploitation - user:
https://edu.defensive-security.com/view/courses/linux-attack-detection-and-live-forensics-v2-0/3341314-initial-access-ta0001/11244659-edr-t6261-remote-uaf-exploitation-user [UPDATED => Tetragon Prevention Policy added]
-
EDR-T6105 - Apache HTTP CVE-2021-41773:
https://edu.defensive-security.com/view/courses/linux-attack-detection-and-live-forensics-v2-0/3341314-initial-access-ta0001/11037854-edr-t6105-apache-http-cve-2021-41773 [UPDATED => Tetragon Prevention Policy added]
-
EDR-T6354 - Remote UAF+Heap Overflow:
https://edu.defensive-security.com/view/courses/linux-attack-detection-and-live-forensics-v2-0/3341314-initial-access-ta0001/11037858-edr-t6354-remote-uaf-heap-overflow [UPDATED => Tetragon Prevention Policy added]
-
EDR-T6416 - React2shell - CVE-2025-55182:
https://edu.defensive-security.com/view/courses/linux-attack-detection-and-live-forensics-v2-0/3341314-initial-access-ta0001/11108001-edr-t6416-react2shell-cve-2025-55182 [UPDATED => Tetragon Prevention Policy added]
-
-
26.04.2026:
-
EDR-T6455 - Fake TLS ClientHello DPI bypass:
-
-
20.04.2026:
-
EDR-T6450 - K8S Ingress-NGINX CVE-2025-1974:
-
PANIX:
-
-
19.04.2026:
-
16.04.2026:
-
EDR-T6039 - File Transfer to a hidden directory:
-
EDR-T6011 - PHP Webshells:
-
-
15.04.2026:
-
8.04.2026:
-
7.04.2026:
-
Memory/mquire:
-
Memory/RAM acquisition:
-
Memory/Volatility3 Framework:
-
Host/go-journalctl:
-
-
1.04.2026:
-
31.03.2026:
-
26.03.2026:
-
EDR-T6317 - SOA/ECS DNS C2 Channel:
-
Host/Exploration of /proc:
-
-
7.03.2026:
-
9.02.2026:
-
EDR-T6439 - Malasada .so to Shellcode Loader:
-
-
8.02.2026:
-
1.02.2026:
-
Active Defense, PT, DE & Assume Breach:
-
Host/Tetragon Runtime Security:
-
Host/Falco Runtime Security:
-
-
28.01.2026:
-
Falco Deployment in K8S
-
Host/Elastic Security Agent:
-
-
27.01.2026:
-
K8S Grafana + PostgreSQL RCE:
-
EDR-T6167 - BOF Loading with BOF-Stager:
-
-
22.01.2026:
-
K8S Static Hidden Pod:
-
K8S Security Scanners:
-
-
21.01.2026:
-
Kubernetes Section:
-
Linux Hardening Guide:
-
EDR-T6359 - UAF Cross-cache Dirty Pipe LPE:
-
Decloaker:
-
-
14.01.2026:
-
EDR-T6212 - Emp3r0r HTTP2 AES Stager C2:
-
-
7.12.2025:
-
Initial release
-