Linux Audio Capture via arecord and ecasound (memfd_create)
Detects Linux execution of arecord for audio capture and ecasound using memfd_create for in-memory data handling.
FreeUnreviewedSigmalowv1
linux-audio-capture-via-arecord-and-ecasound-memfd-create-a7af2487
title: Linux Audio Capture via arecord and ecasound (memfd_create)
id: 5c831dac-c981-4527-8745-88a5809ca569
status: test
description: This rule flags Linux processes attempting audio capture by executing arecord with verbose and raw audio parameters, and by spotting ecasound creating memory-backed files via the memfd_create syscall. Audio recording can be used for surveillance, credential harvesting in some environments, or reconnaissance prior to further actions. The detection relies on auditd telemetry for process execution (execve) and syscall events, including arecord command-line arguments and ecasound running with memfd_create.
references:
- https://linux.die.net/man/1/arecord
- https://linuxconfig.org/how-to-test-microphone-with-audio-linux-sound-architecture-alsa
- https://manpages.debian.org/unstable/ecasound/ecasound.1.en.html
- https://ecasound.seul.org/ecasound/Documentation/examples.html#fconversions
- https://github.com/SigmaHQ/sigma/blob/master/rules/linux/auditd/lnx_auditd_audio_capture.yml
author: Pawel Mazur, Milad Cheraghi, Huntrule Team
date: 2021-09-04
modified: 2025-12-05
tags:
- attack.collection
- attack.t1123
logsource:
product: linux
service: auditd
detection:
selection_execve:
type: EXECVE
a0: arecord
a1: -vv
a2: -fdat
selection_syscall_memfd_create:
type: SYSCALL
exe|endswith: /ecasound
SYSCALL: memfd_create
condition: 1 of selection_*
falsepositives:
- Unknown
level: low
license: DRL-1.1
related:
- id: a7af2487-9c2f-42e4-9bb9-ff961f0561d5
type: derived
What it detects
This rule flags Linux processes attempting audio capture by executing arecord with verbose and raw audio parameters, and by spotting ecasound creating memory-backed files via the memfd_create syscall. Audio recording can be used for surveillance, credential harvesting in some environments, or reconnaissance prior to further actions. The detection relies on auditd telemetry for process execution (execve) and syscall events, including arecord command-line arguments and ecasound running with memfd_create.
Known false positives
- Unknown
Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.