Observed arrival · 2026-08-30
Corebytes — Linux Syscall Field Guide
A defender-focused atlas that maps Linux system calls to malware behaviors and investigation signals.
Field notes
Corebytes uses a behavior-first structure rather than treating individual syscall names as detection verdicts. Its sections connect calls such as execve, mmap, socket, setns, and ptrace to observable context, including ancestry, writable paths, destination rarity, namespace entry, and cross-process writes. The page also notes architecture and kernel-version differences and presents itself as eBPF / auditd ready, though the extract does not establish the depth of those integrations.
Observed signals
Read the marks
Editorial observations of this landing page, not a rating.
One card from the complete issue