Linux auditd: BPFDoor .pid or .lock file access in /var/run

Alerts on auditd-monitored access to specific /var/run .pid and .lock files associated with BPFDoor-style behavior.

FreeReviewedSigma · High · v3
Product
linux
Service
auditd
Author
Rafal Piasecki (SigmaHQ), DRL 1.1
Published
2022-08-10
Updated
2026-07-31
title: "Linux auditd: BPFDoor .pid or .lock file access in /var/run"
id: 18519e6c-0122-42b8-9ef5-18f9dec53647
status: test
description: This rule flags access to specific BPFDoor-related PID and lock files under /var/run. Attackers may create or modify these files to persist, coordinate, or masquerade as legitimate system activity. It relies on Linux auditd telemetry reporting PATH events for the listed .pid and .lock files.
references:
  - https://www.sandflysecurity.com/blog/bpfdoor-an-evasive-linux-backdoor-technical-analysis/
  - https://www.elastic.co/security-labs/a-peek-behind-the-bpfdoor
  - https://www.rapid7.com/blog/post/tr-bpfdoor-telecom-networks-sleeper-cells-threat-research-report/
  - https://github.com/rapid7/Rapid7-Labs/blob/741c7196ec12a0a56b63463d1fd726ff14d3a97a/BPFDoor/rapid7_detect_bpfdoor.sh
  - https://github.com/SigmaHQ/sigma/blob/master/rules/linux/auditd/path/lnx_auditd_bpfdoor_file_accessed.yml
author: Rafal Piasecki, Huntrule Team
date: 2022-08-10
modified: 2026-03-30
tags:
  - attack.execution
  - attack.t1106
  - attack.t1059
logsource:
  product: linux
  service: auditd
detection:
  selection:
    type: PATH
    name:
      - /var/run/aepmonend.pid
      - /var/run/auditd.lock
      - /var/run/cma.lock
      - /var/run/console-kit.pid
      - /var/run/consolekit.pid
      - /var/run/daemon.pid
      - /var/run/hald-addon.pid
      - /var/run/hald-smartd.pid
      - /var/run/haldrund.pid
      - /var/run/hp-health.pid
      - /var/run/hpasmlit.lock
      - /var/run/hpasmlited.pid
      - /var/run/kdevrund.pid
      - /var/run/lldpad.lock
      - /var/run/mcelog.pid
      - /var/run/system.pid
      - /var/run/uvp-srv.pid
      - /var/run/vmtoolagt.pid
      - /var/run/xinetd.lock
  condition: selection
falsepositives:
  - Unlikely
level: high
license: DRL-1.1
related:
  - id: 808146b2-9332-4d78-9416-d7e47012d83d
    type: derived