ASLR Disabled Via Sysctl or Direct Syscall - Linux

 Original Source: [Sigma source]
Title: ASLR Disabled Via Sysctl or Direct Syscall - Linux
Status: experimental
Description:Detects actions that disable Address Space Layout Randomization (ASLR) in Linux, including: - Use of the `personality` syscall with the ADDR_NO_RANDOMIZE flag (0x0040000) - Modification of the /proc/sys/kernel/randomize_va_space file - Execution of the `sysctl` command to set `kernel.randomize_va_space=0` Disabling ASLR is often used by attackers during exploit development or to bypass memory protection mechanisms. A successful use of these methods can reduce the effectiveness of ASLR and make memory corruption attacks more reliable.
References:
  -https://github.com/CheraghiMilad/bypass-Neo23x0-auditd-config/blob/f1c478a37911a5447d5ffcd580f22b167bf3df14/personality-syscall/README.md
  -https://man7.org/linux/man-pages/man2/personality.2.html
  -https://manual.cs50.io/2/personality
  -https://linux-audit.com/linux-aslr-and-kernelrandomize_va_space-setting/
Author: Milad Cheraghi
Date: 2025-05-26
modified:2025-12-05
Tags:
  • -'attack.privilege-escalation'
  • -'attack.stealth'
  • -'attack.defense-impairment'
  • -'attack.t1685'
  • -'attack.t1055.009'
Logsource:
  • product: linux
  • service: auditd
Detection:
  selection_syscall:
    type: 'SYSCALL'
    SYSCALL: 'personality'
    a0: '40000'
  selection_sysctl:
    type: 'EXECVE'
    a0: 'sysctl'
    a1: '-w'
    a2: 'kernel.randomize_va_space=0'
  condition:1 of selection_*
Falsepositives:
  -Debugging or legitimate software testing
Level: high