Skip to content
Better HN
Top
New
Best
Ask
Show
Jobs
Search
⌘K
undefined | Better HN
0 points
harryfyx
2y ago
0 comments
Share
I don't know reverse engineering. But, I guess the ultimate solution would be running a custom OS to fake ptrace results in the kernel level?
0 comments
default
newest
oldest
scandinavian
2y ago
You can just use LD_PRELOAD to load your own version of ptrace. Not as stealthy though.
pizzapim
2y ago
Another way is to load a eBPF program or kernel module for this purpose.
j
/
k
navigate · click thread line to collapse