{"id":"T1055.014","name":"VDSO Hijacking","url":"https://attack.mitre.org/techniques/T1055/014","tactics":["stealth","privilege-escalation"],"platforms":["Linux"],"live":true,"revoked":false,"deprecated":false,"revoked_by":null,"detection_strategies":[{"id":"DET0448","stix_id":"x-mitre-detection-strategy--b511a320-18a6-46ff-9588-85065c44312f","name":"Detection Strategy for VDSO Hijacking on Linux","url":"https://attack.mitre.org/detectionstrategies/DET0448","analytics":[{"id":"AN1241","stix_id":"x-mitre-analytic--bfc7e981-ca7e-4b1b-a692-65a8867a7a89","name":"Analytic 1241","description":"Detects the redirection of syscall execution flow via modification of VDSO code stubs or GOT entries to load and execute a malicious shared object through mmap and ptrace.","url":"https://attack.mitre.org/detectionstrategies/DET0448#AN1241","platforms":["Linux"],"log_source_references":[{"name":"auditd:SYSCALL","channel":"ptrace, mmap, mprotect, open, dlopen","data_component":"DC0021","data_component_name":"OS API Execution","log_source_slug":"auditd-syscall"},{"name":"auditd:memprotect","channel":"change from PROT_READ|PROT_WRITE to PROT_EXEC","data_component":"DC0020","data_component_name":"Process Modification","log_source_slug":"auditd-memprotect"},{"name":"auditd:file-events","channel":"open of suspicious .so from non-standard paths","data_component":"DC0016","data_component_name":"Module Load","log_source_slug":"auditd-file-events"},{"name":"linux:osquery","channel":"child process invoking dynamic linker post-ptrace","data_component":"DC0032","data_component_name":"Process Creation","log_source_slug":"linux-osquery"}],"mutable_elements":[{"field":"SuspiciousSharedObjectPathRegex","description":"Regex to filter dynamic library paths outside of `/lib`, `/usr/lib`, etc. (e.g., `/tmp`, `/dev/shm`)"},{"field":"TimeWindow_PtraceToMmap","description":"Max delay allowed between ptrace attach and mmap/mprotect execution in target process"},{"field":"ExecMemoryProtectionThreshold","description":"Flag when executable memory mappings deviate from normal runtime behavior"},{"field":"AnomalousParentProcessList","description":"Parent processes unlikely to legitimately call ptrace (e.g., nginx, apache2, sshd)"}],"live":true,"detection_strategies":["DET0448"],"techniques":["T1055.014"]}],"live":true,"version":"1.0","techniques":["T1055.014"]}],"sigma_rules":[],"kev_cves":[],"_built":"2026-08-24 19:45 UTC","_attack_version":"19.2","_sigma_commit":"da9bb07d642a2826e89702445d32c795209ec108"}