{"id":"T1055.008","name":"Ptrace System Calls","url":"https://attack.mitre.org/techniques/T1055/008","tactics":["stealth","privilege-escalation"],"platforms":["Linux"],"live":true,"revoked":false,"deprecated":false,"revoked_by":null,"detection_strategies":[{"id":"DET0203","stix_id":"x-mitre-detection-strategy--c2768ab6-522f-4b88-b3f7-a30230208ceb","name":"Detection Strategy for Ptrace-Based Process Injection on Linux","url":"https://attack.mitre.org/detectionstrategies/DET0203","analytics":[{"id":"AN0579","stix_id":"x-mitre-analytic--d9bcfaee-d2d1-4673-b834-5c219f8dba9b","name":"Analytic 0579","description":"Detects ptrace-based process injection by correlating audit logs of ptrace syscalls, memory modifications (e.g., poketext, pokedata), and suspicious register manipulation on a target process not normally debugged by the originator. Alerts on processes attempting to ptrace non-child or privileged processes, especially those followed by abnormal memory or execution behavior.","url":"https://attack.mitre.org/detectionstrategies/DET0203#AN0579","platforms":["Linux"],"log_source_references":[{"name":"auditd:SYSCALL","channel":"mmap, ptrace, process_vm_writev or direct memory ops","data_component":"DC0021","data_component_name":"OS API Execution","log_source_slug":"auditd-syscall"},{"name":"auditd:SYSCALL","channel":"execve","data_component":"DC0032","data_component_name":"Process Creation","log_source_slug":"auditd-syscall"},{"name":"linux:osquery","channel":"state=attached/debugged","data_component":"DC0034","data_component_name":"Process Metadata","log_source_slug":"linux-osquery"}],"mutable_elements":[{"field":"TargetProcessNameFilter","description":"List of sensitive or rarely-debugged processes (e.g., sshd, systemd, container daemons) to alert on if ptraced"},{"field":"TimeWindowBetweenPtraceAndMemoryWrite","description":"Threshold time (e.g., <10 seconds) between ptrace attach and pokedata syscall"},{"field":"UserContextMismatch","description":"Flag when UID of tracer differs from UID of target process (e.g., privilege escalation or container breakout)"},{"field":"ProcessRelationshipConstraint","description":"Allowlist relationships (e.g., parent-child) under which ptrace is considered benign"}],"live":true,"detection_strategies":["DET0203"],"techniques":["T1055.008"]}],"live":true,"version":"1.0","techniques":["T1055.008"]}],"sigma_rules":[],"kev_cves":[],"_built":"2026-08-24 19:45 UTC","_attack_version":"19.2","_sigma_commit":"da9bb07d642a2826e89702445d32c795209ec108"}