
Hunting payloads in Linux extended file attributes
Source: YouTube · SANS Digital Forensics and Incident Response · published Dec 10, 2025 · 22:06
Shabier Mer demonstrates how Linux extended file attributes (xattrs) can be abused to hide malware payloads and provides detection strategies for defenders 0:00.
Key Takeaways:
• Extended file attributes are key-value pairs in Linux filesystems that can store arbitrary data, functioning similarly to Windows Alternate Data Streams and creating a potential attack surface 0:00.
• Mer's proof-of-concept splits an XOR and base64-encoded reverse shell payload across multiple files' xattrs, demonstrating how attackers can store malicious code without creating suspicious files 0:23.
• Detection approaches include getfattr for recursive scanning, auditd with custom rules to monitor xattr activity, and custom tools that identify suspicious binary content within attributes 0:45.
Defenders should restrict file write permissions, implement SELinux controls, and verify how backup systems handle extended attributes to mitigate this hiding technique.
Sources:
Generate CPE Credits
Generate a professional CPE document from this video's transcript.
Estimated credit: 0.5 CPE hours
Estimate uses the video runtime (1 hour ≈ 1 CPE, rounded to the nearest 0.5, minimum 0.5, maximum 2.0). The final amount can be lower after review, never higher.
Topic: Malware Analysis. Commonly maps to: Security Operations, Security Architecture and Engineering. Exact CISSP domains are assigned during generation.
Free account. One generation at a time, with a daily limit.
CPEBuddy is independent and not affiliated with or endorsed by ISC2, ISACA, or any certification body. Exports are formatted for common CPE submissions; acceptance is at your certification body's discretion.
Transcript Preview
First 800 characters of the transcript
Shabier Mer is uh he's from Belgium. He's been um a science instructors for all of for a lot of years. >> Not not as long as you but >> not but many many years already. H he teaches especially he's a specialized in in malware analysis and uh basically he's a reference in the community. He I don't know if many of you are familiar with this internet storm center. It's basically um an organization started by the Sans Institute around year 2000. So that's that's basically 25 years ago. Shave is a is a is basically um one of the engines and one of the brains be behind the IC and he's also doing he's a consultants if free soul doing consulting all over the place uh blue team most of the time and I was wondering is like he's doing all this consulting teaching for sons doing his uh his research uh…