Skip to main content

classify_signal_handler

Function classify_signal_handler 

Source
pub fn classify_signal_handler(signal: u32, handler: u64) -> bool
Expand description

Classify whether a signal handler configuration is suspicious.

Flags SIG_IGN for SIGTERM/SIGHUP (anti-termination), custom handlers for SIGSEGV (self-healing), and any SIGKILL handler (rootkit indicator).