Dynamic linker hijacking of a child process

injection_preload_env

Starts a child process with LD_PRELOAD (or DYLD_INSERT_LIBRARIES on macOS) pointing at a library in the sandbox, the standard Unix code-injection route. The library is deliberately not a loadable object, so nothing can execute; the loader's attempt to preload it is the observable event.

Severity high how bad it would be if it were real
Expected outcome Something should notice
Platforms 2 macOS, Linux
Isolation subprocess runs in its own process, so a kill is a measurement

What it needs before it will run

  • --i-understand

    Needs explicit consent: this test changes machine state or fetches real offensive tooling.

Gates are cumulative and none of them is implied by another: see the three gates for why they are separate decisions.

ATT&CK techniques it exercises

MITRE ATT&CK techniques this test maps to.
Technique Name Tactic Across public reports
T1574.006 Dynamic Linker Hijacking Defense Evasion coverage statistics

How often anything notices

Not enough data: fewer than 3 public reports have run this test, so no rate is published for it. Groups below that threshold are withheld everywhere on the site — with one or two contributors an average is one organisation's result with a percent sign after it.

Other process injection tests

Other tests in the Process injection category.
Test What it does Severity
Remote thread injection into a child process injection_remote_thread Performs the classic OpenProcess / VirtualAllocEx / WriteProcessMemory / CreateRemoteThread sequence against a child process this test starts itself, … critical
ptrace attach to a child process injection_ptrace_attach Attaches to a child process with ptrace, reads its registers and detaches again. On Linux this is the equivalent of a debugger taking over another pro… high

Catalogue generated from client 0.1.0. A test's behaviour can change between releases; this page describes the version named here.