|
|
|
|
|
by amscanne
809 days ago
|
|
There is no ‘system()’ syscall, and fork/exec would be extremely common for opensshd — it’s what it does to spawn new shells which go on to do anything. I’m not arguing with the point, but this is a great place to hide — very difficult to have meaningful detection rules even for a sophisticated sysadmin. |
|
I _think_ it’ll look very different in ps —-forest output.