You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Describe the bug
fd name by d_dname(just like kernel function does). For now, anonymous pipe is an empty string in Hades while it's pipe[xxxx] in Elkeid. This is very important when we deal with some reverse shell things. We should look into how d_name works in kernel.
But for now, we can still detect the socket...
Describe the bug
fd name by d_dname(just like kernel function does). For now, anonymous pipe is an empty string in
Hades
while it'spipe[xxxx]
in Elkeid. This is very important when we deal with some reverse shell things. We should look into how d_name works in kernel.But for now, we can still detect the socket...
Screenshots
In Hades:
In Elkeid:
The text was updated successfully, but these errors were encountered: