|Threat Protection for Linux (formerly Second Look)|
Threat Protection for Linux® is designed for use by investigators who need quick, easy, and effective Linux memory acquisition and analysis capabilities. Threat Protection for Linux is a product of Forcepoint.
Threat Protection for Linux preserves the volatile system state, capturing evidence and information that does not exist on disk and may otherwise be lost as an investigation proceeds. A command-line script allows for acquisition of memory from running systems without introducing any additional software. A memory access driver is provided for use on systems without a native interface to physical memory.
Threat Protection for Linux interprets live system memory or captured memory images, detecting and reverse engineering malware, including stealthy kernel rootkits and backdoors. A kernel integrity verification approach is utilized to compare the Linux kernel in memory with a reference kernel. Pikewerks provides thousands of reference kernels derived from original distribution kernel packages, and a script for creating reference kernels for other systems, such as those running custom kernels.
Threat Protection for Linux also applies an integrity verification approach for the analysis of each process in memory. This enables it to detect unauthorized applications as well as stealthy user-level malware.
Threat Protection for Linux is regularly updated to support analysis of the latest kernels and the most commonly used Linux distributions. The following are its capabilities as of August 2016:
- Supported target kernels: 2.6.x through 3.x
- Supported target architectures: x86 32- and 64-bit
- Supported target distributions: Debian, RHEL/CentOS, Ubuntu, Fedora, SUSE, and more!