difficulties with Linux telemetry

0001-01-01

In sshbackdors-dumont2018, they mention more than once that they had a lack of data and telemetry on Linux systems.

Eset is a respectable company and I’m sure they have people on staff that are fine Linux systems engineers, capable of configuring logging and monitoring systems. If they are having problems, I’m sure that others are, too.

Anecdotally, I run into more people that are more skilled and knowledgeable with Windows than Linux at work. This seems like its typical based on talking with people at meetups and reading blog posts and browsing social media. I’ve met several brilliant analysts that were lost when it came time to deal with some Linux malware due to both unfamiliarity with tools to analyze ELF files and the lack of skills and knowledge to operate on a Linux system.

It is my experience that out of the box or with the help of some common tools found in pretty much every Linux distribution’s packaging system, Linux offers a brilliant set of tools to generate appropriate telemetry. The stuff to get it done is there, but you have to enable and configure it, which can be quite a chore.


Links to this note