Linux Runtime Security & Binary Exploitation Mastery

@amitmund July 09, 2026

Linux Runtime Security & Binary Exploitation Mastery

The Complete Beginner to Advanced Guide to Linux Runtime Security, ELF Internals, Dynamic Linker, LD_PRELOAD, Runtime Integrity, Anti-Rootkits, Process Injection, execve(), Shellcode, Linker Hijacking, Container Escape, Memory Forensics, and Enterprise Runtime Protection


Course Goal

This course teaches everything that happens after a Linux executable is launched, from the moment execve() is called until the process exits.

Unlike Linux Security (system protection) or Linux Kernel courses (kernel internals), this course focuses on runtime behavior, dynamic linking, memory manipulation, process security, runtime integrity, rootkits, containers, malware techniques, and runtime detection.

The emphasis is on understanding, detection, hardening, and defense. Hands-on labs should be performed only in isolated, authorized lab environments.


Prerequisites

  • Linux Mastery
  • Linux Security Mastery
  • Linux Hardening
  • Linux Observability
  • Linux Performance Tuning
  • C Programming
  • Operating Systems
  • Computer Architecture

Course Structure


Module 1 — Linux Program Execution

Chapter 1 — From Source Code to Running Process

  • C Compilation
  • Object Files
  • Linking
  • ELF
  • Executable Layout
  • Loader
  • Runtime

Chapter 2 — execve()

Learn

  • execve() lifecycle
  • Process replacement
  • argv
  • envp
  • Auxiliary Vector
  • Process image
  • Kernel responsibilities
  • Userspace initialization

Chapter 3 — Process Startup

  • _start
  • crt1.o
  • libc initialization
  • __libc_start_main
  • main()
  • exit()

Chapter 4 — ELF Deep Dive

  • ELF Header
  • Program Header
  • Section Header
  • Relocations
  • GOT
  • PLT
  • Symbol Tables

Module 2 — Dynamic Linker

Chapter 5 — Dynamic Linking

  • Static vs Dynamic
  • Shared Libraries
  • Loader
  • Dependency Resolution

Chapter 6 — ld-linux

  • ld-linux.so
  • Search Paths
  • Cache
  • Library Resolution
  • Loader Algorithms

Chapter 7 — Dynamic Loader Internals

  • Relocations
  • Symbol Resolution
  • Lazy Binding
  • Immediate Binding

Chapter 8 — GOT & PLT

  • GOT
  • GOT overwrite (concepts)
  • PLT
  • Function Resolution

Chapter 9 — Symbol Resolution

  • Weak Symbols
  • Strong Symbols
  • Symbol Visibility
  • Symbol Versioning

Module 3 — LD_PRELOAD

Chapter 10 — Introduction to LD_PRELOAD

  • Environment Variables
  • Library Injection
  • Symbol Override
  • Dynamic Hooking

Chapter 11 — How LD_PRELOAD Works

Internal Working

  • Loader
  • Search Order
  • Library Priority
  • Symbol Lookup

Chapter 12 — Safe Runtime Instrumentation

Examples

  • Logging
  • Profiling
  • Debugging
  • Function tracing
  • Metrics collection
  • API monitoring

Chapter 13 — LD_AUDIT

  • Runtime Auditing
  • Symbol Monitoring
  • Library Monitoring

  • LD_LIBRARY_PATH
  • rpath
  • runpath
  • ldconfig

Module 4 — Runtime Integrity

Chapter 15 — Runtime Integrity

Learn

  • Code Integrity
  • Library Integrity
  • Memory Integrity
  • Binary Integrity

Chapter 16 — Integrity Verification

  • File Hashes
  • ELF Verification
  • Signatures
  • Measurements

Chapter 17 — Runtime Attestation

  • IMA (Integrity Measurement Architecture)
  • EVM
  • TPM-backed measurements
  • Measured Boot

Chapter 18 — Process Trust

  • Trusted Processes
  • Runtime Policies
  • Execution Policies

Module 5 — Linux Memory

Chapter 19 — Process Memory Layout

  • Stack
  • Heap
  • mmap
  • Shared Libraries
  • TLS
  • VDSO

Chapter 20 — Virtual Memory

Chapter 21 — Address Space Layout

Chapter 22 — Memory Mapping

Chapter 23 — Copy-on-Write

Chapter 24 — ASLR

Chapter 25 — RELRO

Chapter 26 — PIE

Chapter 27 — NX


Module 6 — Runtime Instrumentation

Chapter 28 — ptrace

  • Debugging
  • Observability
  • Process inspection
  • Security implications

Chapter 29 — eBPF Runtime Monitoring

Chapter 30 — uprobes

Chapter 31 — kprobes

Chapter 32 — perf

Chapter 33 — auditd


Module 7 — Runtime Threat Detection

Chapter 34 — Detecting Library Tampering

Chapter 35 — Detecting Suspicious Environment Variables

Chapter 36 — Detecting Unauthorized Shared Objects

Chapter 37 — Detecting Process Memory Anomalies

Chapter 38 — Detecting Unexpected Child Processes

Chapter 39 — Detecting Runtime Drift


Module 8 — Dynamic Linker Security

Chapter 40 — Secure Linking

Chapter 41 — Trusted Libraries

Chapter 42 — Library Search Path Hardening

Chapter 43 — Loader Security

Chapter 44 — Environment Sanitization

Chapter 45 — Secure Build Flags


Module 9 — Runtime Malware Concepts (Defensive Focus)

Chapter 46 — Rootkits

Learn

  • User-space Rootkits
  • Kernel Rootkits
  • Persistence Concepts
  • Detection Strategies
  • Defensive Monitoring

Chapter 47 — Runtime Hooking

  • API Hooking (conceptual)
  • Function Interposition
  • Defensive Detection
  • Integrity Monitoring

Chapter 48 — Process Injection (Overview)

  • Common categories
  • Detection approaches
  • Telemetry
  • Defensive controls

Chapter 49 — Shellcode Fundamentals

Learn

  • What shellcode is
  • Historical context
  • Memory execution protections
  • Defensive detection techniques

Chapter 50 — Runtime Memory Analysis

  • Memory Maps
  • Anonymous Pages
  • Executable Memory
  • Shared Objects

Module 10 — Anti-Rootkit Engineering

Chapter 51 — Rootkit Detection

Chapter 52 — Integrity Scanning

Chapter 53 — Hidden Process Detection

Chapter 54 — Hidden Files Detection

Chapter 55 — Kernel Module Monitoring

Chapter 56 — Memory Forensics

Chapter 57 — Volatility Framework

Chapter 58 — LiME Memory Acquisition


Module 11 — Process Monitoring

Chapter 59 — Process Trees

Chapter 60 — Parent/Child Relationships

Chapter 61 — Environment Variables

Chapter 62 — File Descriptors

Chapter 63 — Process Capabilities

Chapter 64 — Namespaces


Module 12 — Containers & Runtime Security

Chapter 65 — Container Runtime

Chapter 66 — runc

Chapter 67 — containerd

Chapter 68 — OCI Runtime

Chapter 69 — Namespaces

Chapter 70 — cgroups


Chapter 71 — Container Isolation

  • Filesystem
  • Network
  • PID
  • User
  • Mount
  • IPC

Chapter 72 — Container Escape (Defensive Perspective)

Learn

  • Isolation boundaries
  • Misconfiguration risks
  • Detection
  • Hardening
  • Least privilege
  • Runtime protection

Module 13 — Runtime Security Platforms

Chapter 73 — Falco

Chapter 74 — AppArmor

Chapter 75 — SELinux

Chapter 76 — seccomp

Chapter 77 — Landlock

Chapter 78 — Open Policy Agent


Module 14 — Runtime Observability

Chapter 79 — OpenTelemetry

Chapter 80 — Prometheus

Chapter 81 — eBPF Tracing

Chapter 82 — Grafana

Chapter 83 — Loki


Module 15 — Enterprise Runtime Security

Chapter 84 — Zero Trust Runtime

Chapter 85 — Supply Chain Integrity

Chapter 86 — Signed Binaries

Chapter 87 — SBOM

Chapter 88 — Runtime Compliance


Module 16 — Advanced Kernel Features

Chapter 89 — Integrity Measurement Architecture

Chapter 90 — Secure Boot

Chapter 91 — TPM

Chapter 92 — Kernel Lockdown

Chapter 93 — Kernel Keyrings


Module 17 — Troubleshooting

Chapter 94 — Loader Errors

Chapter 95 — Missing Libraries

Chapter 96 — Symbol Resolution Problems

Chapter 97 — Memory Corruption Detection

Chapter 98 — Runtime Integrity Failures


Module 18 — Interview Preparation

Chapter 99 — Linux Runtime Questions

Chapter 100 — ELF Questions

Chapter 101 — Dynamic Linking Questions

Chapter 102 — Runtime Security Questions

Chapter 103 — Container Runtime Questions

Chapter 104 — Mock Interviews


Commands & Tools Covered

ELF

  • readelf
  • objdump
  • nm
  • strings
  • file
  • ldd
  • eu-readelf

Runtime

  • lsof
  • pmap
  • procfs
  • strace
  • ltrace
  • perf
  • gdb

Memory

  • smem
  • vmstat
  • pmap
  • procfs

Integrity

  • sha256sum
  • rpm
  • debsums
  • IMA tools

Monitoring

  • auditd
  • Falco
  • eBPF
  • bpftrace
  • bpftool

Technologies Covered

  • ELF
  • glibc
  • ld-linux
  • Dynamic Loader
  • Shared Libraries
  • LD_PRELOAD
  • LD_AUDIT
  • GOT
  • PLT
  • RELRO
  • PIE
  • ASLR
  • NX
  • seccomp
  • SELinux
  • AppArmor
  • eBPF
  • Falco
  • IMA
  • TPM
  • OCI
  • containerd
  • runc
  • procfs
  • sysfs

Every Chapter Includes

Every chapter follows the same professional learning structure:

  • Learning Objectives
  • Theory
  • Internal Working
  • Linux Kernel Internals
  • Dynamic Linker Internals
  • ELF Internals
  • Memory Layout Diagrams
  • Runtime Architecture
  • Mermaid Diagrams
  • ASCII Diagrams
  • Sequence Diagrams
  • Safe Demonstration Examples
  • Production Monitoring Examples
  • Observability Techniques
  • Security Notes
  • Detection Strategies
  • Hardening Best Practices
  • Common Mistakes
  • Troubleshooting Guide
  • Hands-on Defensive Labs
  • Mini Projects
  • Exercises
  • Quiz
  • Interview Questions
  • Cheat Sheet
  • Summary
  • References
  • Further Reading

Hands-on Labs

  1. Analyze ELF binaries with readelf and objdump.
  2. Trace process startup using strace.
  3. Observe dynamic library loading with ldd.
  4. Inspect process memory maps via /proc/<pid>/maps.
  5. Monitor runtime behavior using eBPF and bpftrace.
  6. Configure and test AppArmor or SELinux policies.
  7. Build runtime dashboards with Falco, Prometheus, and Grafana.
  8. Measure file integrity with IMA and checksums.
  9. Explore container namespaces and isolation boundaries.
  10. Investigate a simulated runtime integrity incident in a lab environment.

Capstone Projects

  1. Linux Runtime Integrity Monitoring Platform
  2. Enterprise Runtime Security Dashboard
  3. ELF Binary Analysis Toolkit
  4. Dynamic Linker Visualization Tool
  5. Runtime Integrity Verification Framework
  6. Container Runtime Security Monitoring Platform
  7. eBPF-based Runtime Telemetry System
  8. Production Process Behavior Analyzer
  9. Linux Memory Observation Toolkit
  10. Enterprise Runtime Security Architecture

Estimated Course Size

  • 18 Modules
  • 104 Chapters
  • 5,500+ Pages
  • 2,500+ Commands & Analysis Examples
  • 1,000+ Architecture & Runtime Diagrams
  • 300+ Hands-on Defensive Labs
  • 100+ Production Case Studies
  • Complete Linux Runtime Security & Dynamic Linking Mastery

Final Outcome

After completing this learning track, you will be able to:

  • Explain the complete Linux executable lifecycle from execve() through dynamic linking to process termination.
  • Understand ELF binaries, the dynamic linker, shared libraries, and runtime symbol resolution in depth.
  • Use tools such as readelf, objdump, strace, perf, bpftrace, and /proc to inspect and troubleshoot running processes.
  • Design and implement runtime integrity monitoring using Linux security features, eBPF, and observability platforms.
  • Detect signs of runtime tampering, unauthorized library loading, suspicious process behavior, and container runtime anomalies.
  • Harden Linux systems against runtime attacks using secure linking, integrity measurement, policy enforcement, and least-privilege techniques.
  • Confidently perform as a Linux Security Engineer, Platform Security Engineer, SRE, DevSecOps Engineer, Incident Responder, or Distinguished Systems Engineer.
0 Likes
19 Views
0 Comments

Filters

No filters available for this view.

Reset All