Expand description
Timer/signal FD abuse detection.
Functionsยง
- is_
suspicious_ fd_ count - Classify whether a process has a suspicious number of timer/signal/event file descriptors by comparing against a threshold.
- scan_
fd_ abuse - Scan for timerfd/signalfd/eventfd abuse patterns.