Skip to the card

Card 177 of 9992026-08-30 issue

Observed arrival · 2026-08-30

Corebytes — Linux Syscall Field Guide

corebytes.org Observed source
Editorial interest 79/100 Selection signal · not a rating of the site

A defender-focused atlas that maps Linux system calls to malware behaviors and investigation signals.

Landing page captured for the 2026-08-30 issue.

Field notes

Corebytes uses a behavior-first structure rather than treating individual syscall names as detection verdicts. Its sections connect calls such as execve, mmap, socket, setns, and ptrace to observable context, including ancestry, writable paths, destination rarity, namespace entry, and cross-process writes. The page also notes architecture and kernel-version differences and presents itself as eBPF / auditd ready, though the extract does not establish the depth of those integrations.

Observed signals

Read the marks

Editorial observations of this landing page, not a rating.

OpenPublic substance visible
PrettyNotable craft visible
ProPolished or operationally mature
NicheUnusually specific use

One card from the complete issue

The Unserved Branch

223,571 arrived 1,000 judged 999 catalogued Enter the complete issue
corebytes.org

Landing page observed 2026-08-30. The live site may have changed.