#
DIFF.BLOG
New
Following
Discover
Jobs
More
Top Writers
Suggest a blog
Upvotes plugin
Report bug
Contact
About
Privacy
Sign up
The home for great developer writing.
We surface the best developer writing from thousands of independent blogs, updated daily.
Join Diff.blog
TOPICS
When the web shell isn’t on disk: the F5 BIG-IP rootkit that lives in memory
·
·
Sept. 14, 2026, 12:36 p.m.
Linux
Security
dfir
memory-forensics
Cybersecurity
Linux
Incident Response
web-security
Summary
The post discusses a Linux rootkit that targets F5 BIG-IP APM environments, focusing on a PHP web shell concealed within Apache process memory. This revelation challenges traditional file-centric incident response approaches in cybersecurity.
Read full post on andreafortuna.org →
MORE POSTS LIKE THIS
security: Cookie-controlled PHP webshells: A stealthy tradecraft in Linux hosting environments
Sujith Quintelier ·
Apr 2, 2026
Cybersecurity
PHP
ClearFake WebDAV infection chain delivers Amatera stealer, ZigCryptoStealer, and NetSupport Manager
Blog Talosintelligence ·
Sep 8, 2026
Threats
Threat Spotlight
Trusting a self-signed localhost certificate in Chrome on Linux
Daniel Opitz ·
Sep 2, 2026
Linux
Chrome
METR and Redwood Offer Holy #%^@ Postmortem Of The HuggingFace Hack
Thezvi Wordpress ·
Aug 29, 2026
AI
Technology
Three NTFS bugs, one VHD file, and what your logs should already be telling you
andreafortuna ·
Aug 17, 2026
windows
Security
AIM: Building an Agentic Tier-2 SOC Analyst at Cisco Live AMER 2026
Blogs Cisco ·
Jul 7, 2026
Cybersecurity
AI
Discover more posts →
AUTHOR
Advertise
Sponsor diff.blog
Put your product in front of developers who read and write about their craft. One exclusive sponsor at a time.
Become a sponsor →
RECENT POSTS FROM THE AUTHOR
Choose how you want to continue.
Continue with GitHub
Continue with Google
By continuing, you agree to our
Privacy Policy
.