Linux Runtime Security & Binary Exploitation Mastery
Linux Runtime Security & Binary Exploitation Mastery
The Complete Beginner to Advanced Guide to Linux Runtime Security, ELF Internals, Dynamic Linker, LD_PRELOAD, Runtime Integrity, Anti-Rootkits, Process Injection, execve(), Shellcode, Linker Hijacking, Container Escape, Memory Forensics, and Enterprise Runtime Protection
Course Goal
This course teaches everything that happens after a Linux executable is launched, from the moment execve() is called until the process exits.
Unlike Linux Security (system protection) or Linux Kernel courses (kernel internals), this course focuses on runtime behavior, dynamic linking, memory manipulation, process security, runtime integrity, rootkits, containers, malware techniques, and runtime detection.
The emphasis is on understanding, detection, hardening, and defense. Hands-on labs should be performed only in isolated, authorized lab environments.
Prerequisites
- Linux Mastery
- Linux Security Mastery
- Linux Hardening
- Linux Observability
- Linux Performance Tuning
- C Programming
- Operating Systems
- Computer Architecture
Course Structure
Module 1 — Linux Program Execution
Chapter 1 — From Source Code to Running Process
- C Compilation
- Object Files
- Linking
- ELF
- Executable Layout
- Loader
- Runtime
Chapter 2 — execve()
Learn
- execve() lifecycle
- Process replacement
- argv
- envp
- Auxiliary Vector
- Process image
- Kernel responsibilities
- Userspace initialization
Chapter 3 — Process Startup
- _start
- crt1.o
- libc initialization
- __libc_start_main
- main()
- exit()
Chapter 4 — ELF Deep Dive
- ELF Header
- Program Header
- Section Header
- Relocations
- GOT
- PLT
- Symbol Tables
Module 2 — Dynamic Linker
Chapter 5 — Dynamic Linking
- Static vs Dynamic
- Shared Libraries
- Loader
- Dependency Resolution
Chapter 6 — ld-linux
- ld-linux.so
- Search Paths
- Cache
- Library Resolution
- Loader Algorithms
Chapter 7 — Dynamic Loader Internals
- Relocations
- Symbol Resolution
- Lazy Binding
- Immediate Binding
Chapter 8 — GOT & PLT
- GOT
- GOT overwrite (concepts)
- PLT
- Function Resolution
Chapter 9 — Symbol Resolution
- Weak Symbols
- Strong Symbols
- Symbol Visibility
- Symbol Versioning
Module 3 — LD_PRELOAD
Chapter 10 — Introduction to LD_PRELOAD
- Environment Variables
- Library Injection
- Symbol Override
- Dynamic Hooking
Chapter 11 — How LD_PRELOAD Works
Internal Working
- Loader
- Search Order
- Library Priority
- Symbol Lookup
Chapter 12 — Safe Runtime Instrumentation
Examples
- Logging
- Profiling
- Debugging
- Function tracing
- Metrics collection
- API monitoring
Chapter 13 — LD_AUDIT
- Runtime Auditing
- Symbol Monitoring
- Library Monitoring
Chapter 14 — Runtime Library Search
- LD_LIBRARY_PATH
- rpath
- runpath
- ldconfig
Module 4 — Runtime Integrity
Chapter 15 — Runtime Integrity
Learn
- Code Integrity
- Library Integrity
- Memory Integrity
- Binary Integrity
Chapter 16 — Integrity Verification
- File Hashes
- ELF Verification
- Signatures
- Measurements
Chapter 17 — Runtime Attestation
- IMA (Integrity Measurement Architecture)
- EVM
- TPM-backed measurements
- Measured Boot
Chapter 18 — Process Trust
- Trusted Processes
- Runtime Policies
- Execution Policies
Module 5 — Linux Memory
Chapter 19 — Process Memory Layout
- Stack
- Heap
- mmap
- Shared Libraries
- TLS
- VDSO
Chapter 20 — Virtual Memory
Chapter 21 — Address Space Layout
Chapter 22 — Memory Mapping
Chapter 23 — Copy-on-Write
Chapter 24 — ASLR
Chapter 25 — RELRO
Chapter 26 — PIE
Chapter 27 — NX
Module 6 — Runtime Instrumentation
Chapter 28 — ptrace
- Debugging
- Observability
- Process inspection
- Security implications
Chapter 29 — eBPF Runtime Monitoring
Chapter 30 — uprobes
Chapter 31 — kprobes
Chapter 32 — perf
Chapter 33 — auditd
Module 7 — Runtime Threat Detection
Chapter 34 — Detecting Library Tampering
Chapter 35 — Detecting Suspicious Environment Variables
Chapter 36 — Detecting Unauthorized Shared Objects
Chapter 37 — Detecting Process Memory Anomalies
Chapter 38 — Detecting Unexpected Child Processes
Chapter 39 — Detecting Runtime Drift
Module 8 — Dynamic Linker Security
Chapter 40 — Secure Linking
Chapter 41 — Trusted Libraries
Chapter 42 — Library Search Path Hardening
Chapter 43 — Loader Security
Chapter 44 — Environment Sanitization
Chapter 45 — Secure Build Flags
Module 9 — Runtime Malware Concepts (Defensive Focus)
Chapter 46 — Rootkits
Learn
- User-space Rootkits
- Kernel Rootkits
- Persistence Concepts
- Detection Strategies
- Defensive Monitoring
Chapter 47 — Runtime Hooking
- API Hooking (conceptual)
- Function Interposition
- Defensive Detection
- Integrity Monitoring
Chapter 48 — Process Injection (Overview)
- Common categories
- Detection approaches
- Telemetry
- Defensive controls
Chapter 49 — Shellcode Fundamentals
Learn
- What shellcode is
- Historical context
- Memory execution protections
- Defensive detection techniques
Chapter 50 — Runtime Memory Analysis
- Memory Maps
- Anonymous Pages
- Executable Memory
- Shared Objects
Module 10 — Anti-Rootkit Engineering
Chapter 51 — Rootkit Detection
Chapter 52 — Integrity Scanning
Chapter 53 — Hidden Process Detection
Chapter 54 — Hidden Files Detection
Chapter 55 — Kernel Module Monitoring
Chapter 56 — Memory Forensics
Chapter 57 — Volatility Framework
Chapter 58 — LiME Memory Acquisition
Module 11 — Process Monitoring
Chapter 59 — Process Trees
Chapter 60 — Parent/Child Relationships
Chapter 61 — Environment Variables
Chapter 62 — File Descriptors
Chapter 63 — Process Capabilities
Chapter 64 — Namespaces
Module 12 — Containers & Runtime Security
Chapter 65 — Container Runtime
Chapter 66 — runc
Chapter 67 — containerd
Chapter 68 — OCI Runtime
Chapter 69 — Namespaces
Chapter 70 — cgroups
Chapter 71 — Container Isolation
- Filesystem
- Network
- PID
- User
- Mount
- IPC
Chapter 72 — Container Escape (Defensive Perspective)
Learn
- Isolation boundaries
- Misconfiguration risks
- Detection
- Hardening
- Least privilege
- Runtime protection
Module 13 — Runtime Security Platforms
Chapter 73 — Falco
Chapter 74 — AppArmor
Chapter 75 — SELinux
Chapter 76 — seccomp
Chapter 77 — Landlock
Chapter 78 — Open Policy Agent
Module 14 — Runtime Observability
Chapter 79 — OpenTelemetry
Chapter 80 — Prometheus
Chapter 81 — eBPF Tracing
Chapter 82 — Grafana
Chapter 83 — Loki
Module 15 — Enterprise Runtime Security
Chapter 84 — Zero Trust Runtime
Chapter 85 — Supply Chain Integrity
Chapter 86 — Signed Binaries
Chapter 87 — SBOM
Chapter 88 — Runtime Compliance
Module 16 — Advanced Kernel Features
Chapter 89 — Integrity Measurement Architecture
Chapter 90 — Secure Boot
Chapter 91 — TPM
Chapter 92 — Kernel Lockdown
Chapter 93 — Kernel Keyrings
Module 17 — Troubleshooting
Chapter 94 — Loader Errors
Chapter 95 — Missing Libraries
Chapter 96 — Symbol Resolution Problems
Chapter 97 — Memory Corruption Detection
Chapter 98 — Runtime Integrity Failures
Module 18 — Interview Preparation
Chapter 99 — Linux Runtime Questions
Chapter 100 — ELF Questions
Chapter 101 — Dynamic Linking Questions
Chapter 102 — Runtime Security Questions
Chapter 103 — Container Runtime Questions
Chapter 104 — Mock Interviews
Commands & Tools Covered
ELF
- readelf
- objdump
- nm
- strings
- file
- ldd
- eu-readelf
Runtime
- lsof
- pmap
- procfs
- strace
- ltrace
- perf
- gdb
Memory
- smem
- vmstat
- pmap
- procfs
Integrity
- sha256sum
- rpm
- debsums
- IMA tools
Monitoring
- auditd
- Falco
- eBPF
- bpftrace
- bpftool
Technologies Covered
- ELF
- glibc
- ld-linux
- Dynamic Loader
- Shared Libraries
- LD_PRELOAD
- LD_AUDIT
- GOT
- PLT
- RELRO
- PIE
- ASLR
- NX
- seccomp
- SELinux
- AppArmor
- eBPF
- Falco
- IMA
- TPM
- OCI
- containerd
- runc
- procfs
- sysfs
Every Chapter Includes
Every chapter follows the same professional learning structure:
- Learning Objectives
- Theory
- Internal Working
- Linux Kernel Internals
- Dynamic Linker Internals
- ELF Internals
- Memory Layout Diagrams
- Runtime Architecture
- Mermaid Diagrams
- ASCII Diagrams
- Sequence Diagrams
- Safe Demonstration Examples
- Production Monitoring Examples
- Observability Techniques
- Security Notes
- Detection Strategies
- Hardening Best Practices
- Common Mistakes
- Troubleshooting Guide
- Hands-on Defensive Labs
- Mini Projects
- Exercises
- Quiz
- Interview Questions
- Cheat Sheet
- Summary
- References
- Further Reading
Hands-on Labs
- Analyze ELF binaries with
readelfandobjdump. - Trace process startup using
strace. - Observe dynamic library loading with
ldd. - Inspect process memory maps via
/proc/<pid>/maps. - Monitor runtime behavior using eBPF and
bpftrace. - Configure and test AppArmor or SELinux policies.
- Build runtime dashboards with Falco, Prometheus, and Grafana.
- Measure file integrity with IMA and checksums.
- Explore container namespaces and isolation boundaries.
- Investigate a simulated runtime integrity incident in a lab environment.
Capstone Projects
- Linux Runtime Integrity Monitoring Platform
- Enterprise Runtime Security Dashboard
- ELF Binary Analysis Toolkit
- Dynamic Linker Visualization Tool
- Runtime Integrity Verification Framework
- Container Runtime Security Monitoring Platform
- eBPF-based Runtime Telemetry System
- Production Process Behavior Analyzer
- Linux Memory Observation Toolkit
- Enterprise Runtime Security Architecture
Estimated Course Size
- 18 Modules
- 104 Chapters
- 5,500+ Pages
- 2,500+ Commands & Analysis Examples
- 1,000+ Architecture & Runtime Diagrams
- 300+ Hands-on Defensive Labs
- 100+ Production Case Studies
- Complete Linux Runtime Security & Dynamic Linking Mastery
Final Outcome
After completing this learning track, you will be able to:
- Explain the complete Linux executable lifecycle from
execve()through dynamic linking to process termination. - Understand ELF binaries, the dynamic linker, shared libraries, and runtime symbol resolution in depth.
- Use tools such as
readelf,objdump,strace,perf,bpftrace, and/procto inspect and troubleshoot running processes. - Design and implement runtime integrity monitoring using Linux security features, eBPF, and observability platforms.
- Detect signs of runtime tampering, unauthorized library loading, suspicious process behavior, and container runtime anomalies.
- Harden Linux systems against runtime attacks using secure linking, integrity measurement, policy enforcement, and least-privilege techniques.
- Confidently perform as a Linux Security Engineer, Platform Security Engineer, SRE, DevSecOps Engineer, Incident Responder, or Distinguished Systems Engineer.