Hunting Malware and Malicious MCPs in Memory on Kubernetes with FleetDM, Osquery, and YARA

The article demonstrates how FleetDM, Osquery's new yara_process capability, and YARA rules can be combined to detect malware executing entirely in memory at scale. Using Kubernetes and a malicious MCP server as case studies, it shows how security teams can hunt in-memory threats without traditional memory dumps, enabling more effective detection of fileless malware and emerging AI-related attack techniques 

https://holdmybeersecurity.com/2026/07/14/hunting-malware-and-malicious-mcps-in-memory-on-kubernetes-with-fleetdm-osquery-yara

Comments

Popular posts from this blog

Prompt Engineering Demands Rigorous Evaluation

Open-SPDD proposes an open framework for Spec-Driven Development workflows

OWASP ASVS 5.0 Released - Key Updates and What You Need to Know