Hunting Malware and Malicious MCPs in Memory on Kubernetes with FleetDM, Osquery, and YARA
The article demonstrates how FleetDM, Osquery's new yara_process capability, and YARA rules can be combined to detect malware executing entirely in memory at scale. Using Kubernetes and a malicious MCP server as case studies, it shows how security teams can hunt in-memory threats without traditional memory dumps, enabling more effective detection of fileless malware and emerging AI-related attack techniques
Comments
Post a Comment