Linux auditd: BPFDoor .pid or .lock file access in /var/run
Alerts on auditd-monitored access to specific /var/run .pid and .lock files associated with BPFDoor-style behavior.
FreeReviewedSigma · High · v3
- Product
- linux
- Service
- auditd
- Author
- Rafal Piasecki (SigmaHQ), DRL 1.1
- Published
- 2022-08-10
- Updated
- 2026-07-31
ATT&CK techniques
ExecutionRecon
Resource Dev
Initial Access
Persistence
Priv Esc
Defense Evasion
Cred Access
Discovery
Lateral Movement
Collection
C2
Exfiltration
Impact
What it detects
This rule flags access to specific BPFDoor-related PID and lock files under /var/run. Attackers may create or modify these files to persist, coordinate, or masquerade as legitimate system activity. It relies on Linux auditd telemetry reporting PATH events for the listed .pid and .lock files.
Reporting behind it
- sandflysecurity.comhttps://www.sandflysecurity.com/blog/bpfdoor-an-evasive-linux-backdoor-technical-analysis/
- elastic.cohttps://www.elastic.co/security-labs/a-peek-behind-the-bpfdoor
- rapid7.comhttps://www.rapid7.com/blog/post/tr-bpfdoor-telecom-networks-sleeper-cells-threat-research-report/
- github.comhttps://github.com/rapid7/Rapid7-Labs/blob/741c7196ec12a0a56b63463d1fd726ff14d3a97a/BPFDoor/rapid7_detect_bpfdoor.sh
- github.comhttps://github.com/SigmaHQ/sigma/blob/master/rules/linux/auditd/path/lnx_auditd_bpfdoor_file_accessed.yml
Changelog
v3- v3Candidate ingested via manual entry.2026-07-31
- v2Candidate ingested via manual entry.2026-07-31
- v1No changelog recorded for this version.2026-07-30
Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.
linux-auditd-rule-for-bpfdoor-related-pid-and-lock-file-access-under-var-run-808146b2
title: "Linux auditd: BPFDoor .pid or .lock file access in /var/run"
id: 18519e6c-0122-42b8-9ef5-18f9dec53647
status: test
description: This rule flags access to specific BPFDoor-related PID and lock files under /var/run. Attackers may create or modify these files to persist, coordinate, or masquerade as legitimate system activity. It relies on Linux auditd telemetry reporting PATH events for the listed .pid and .lock files.
references:
- https://www.sandflysecurity.com/blog/bpfdoor-an-evasive-linux-backdoor-technical-analysis/
- https://www.elastic.co/security-labs/a-peek-behind-the-bpfdoor
- https://www.rapid7.com/blog/post/tr-bpfdoor-telecom-networks-sleeper-cells-threat-research-report/
- https://github.com/rapid7/Rapid7-Labs/blob/741c7196ec12a0a56b63463d1fd726ff14d3a97a/BPFDoor/rapid7_detect_bpfdoor.sh
- https://github.com/SigmaHQ/sigma/blob/master/rules/linux/auditd/path/lnx_auditd_bpfdoor_file_accessed.yml
author: Rafal Piasecki, Huntrule Team
date: 2022-08-10
modified: 2026-03-30
tags:
- attack.execution
- attack.t1106
- attack.t1059
logsource:
product: linux
service: auditd
detection:
selection:
type: PATH
name:
- /var/run/aepmonend.pid
- /var/run/auditd.lock
- /var/run/cma.lock
- /var/run/console-kit.pid
- /var/run/consolekit.pid
- /var/run/daemon.pid
- /var/run/hald-addon.pid
- /var/run/hald-smartd.pid
- /var/run/haldrund.pid
- /var/run/hp-health.pid
- /var/run/hpasmlit.lock
- /var/run/hpasmlited.pid
- /var/run/kdevrund.pid
- /var/run/lldpad.lock
- /var/run/mcelog.pid
- /var/run/system.pid
- /var/run/uvp-srv.pid
- /var/run/vmtoolagt.pid
- /var/run/xinetd.lock
condition: selection
falsepositives:
- Unlikely
level: high
license: DRL-1.1
related:
- id: 808146b2-9332-4d78-9416-d7e47012d83d
type: derived