Expand description
Shared memory forensics / anomaly detection.
Functionsยง
- is_
suspicious_ shm - Classify whether a shared memory segment has an anomalously high attach
count (
nattch) that exceeds the given threshold. - scan_
shared_ mem_ anomalies - Scan for shared memory anomalies (executable memfd, ELF headers, cross-uid sharing).