Rewriting Every Syscall in a Linux Binary at Load Time
4 points
2 hours ago
| 1 comment
| amitlimaye1.substack.com
| HN
CableNinja
14 minutes ago
[-]
I assume this would break observability through existing methods, right? If you were to strace a process that has been patched, would you see regular syscall data (as if it wasnt patched) or would your syscall replacement appear along the way?
reply