Skip to main content

Identifying attack patterns through kernel frame callstacks

0
Medium
Published: 05/29/2026 (05/29/2026, 13:25:27 UTC)
Source: Reddit BlueTeam

Description

This content describes a novel detection technique using kernel frame callstacks to identify attack patterns by capturing and symbolizing kernel return addresses during system events. It is implemented in the open-source tool Fibratus and aims to enhance detection precision for complex attack flows such as lateral movement via SMB. No specific vulnerability or exploit is described, and no patch or remediation is indicated.

Reddit Discussion

r/blueteamsec·posted by u/rabbitstack
00

Hi all!

I'm the creator of Fibratus - the open-source security sensor for adversary tradecraft detection, protection, and hunting.

Recently, I've been pushing detection engineering deeper into the kernel and uncovered what appears to be a novel approach to identifying attack patterns through kernel frame callstacks.

User-space callstack telemetry has already become a powerful signal leveraged by modern security platforms. But kernel thread return addresses are largely unexplored territory.

So, I made Fibratus capture kernel return addresses for different events (process creation, thread creation, file operations, etc.) and symbolize them into module paths, exposing the exact drivers and kernel subsystems traversed during event execution. The result is a radically richer execution narrative, one that reveals behavioral context traditional telemetry simply cannot see.

This unlocks an entirely new detection surface.

By incorporating kernel callstack summaries directly into detection rules, we can identify highly specific attack flows with exceptional precision. One example: detecting files dropped over SMB and subsequently executed: a classic lateral movement pattern. Check the screenshot for the detection rule example:

SMB Lateral Movement Rule

The kernel callstack becomes the connective tissue between stages of execution, providing durable attribution that is significantly more resistant to spoofing and telemetry tampering.

We're actively building a new generation of detections powered by kernel subsystem context, driver-level execution paths, and low-level behavioral correlations that were previously inaccessible to defenders.

If you’re interested in advanced detection engineering, kernel telemetry, or crafting next-generation behavioral rules, I’d love to connect and exchange ideas. Please let me know your thoughts and ideas, and we'll make sure to ship those rules in the next Fibratus release.

Regards,

Nedim

Also discussed in: r/blueteamsec

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 08/14/2026, 15:57:05 UTC

Technical Analysis

The described approach leverages kernel thread return addresses captured during various system events (e.g., process creation, file operations) and symbolizes them into module paths to reveal detailed kernel-level execution paths. This richer telemetry enables more precise detection rules that can identify specific attack flows, such as lateral movement over SMB, by correlating kernel callstack summaries with behavioral context. The technique improves attribution and resistance to telemetry tampering. It is implemented in the open-source security sensor Fibratus, which focuses on adversary tradecraft detection and hunting at the kernel level. No vulnerabilities or exploits are reported in this content.

Potential Impact

There is no direct security impact such as a vulnerability or exploit. The technique enhances defenders' visibility and detection capabilities for kernel-level attack patterns, potentially improving incident detection and response effectiveness. It does not introduce new risks or require remediation.

Defensive Guidance

No patch or remediation is required as this is a detection methodology rather than a vulnerability. Organizations interested in advanced kernel-level detection may consider deploying or evaluating the Fibratus tool to leverage this capability.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Source Type
reddit
Subreddit
blueteamsec+AskNetsec+Information_Security
Reddit Score
0
Discussion Level
minimal
Content Source
reddit_link_post
Post Type
link
Newsworthiness Assessment
{"score":27,"reasons":["external_link","established_author","very_recent"],"isNewsworthy":true}
Has External Source
true
Trusted Domain
false

Threat ID: 6a1995aae29bf47b50e978fe

Added to database: 05/29/2026, 13:33:30 UTC

Last enriched: 08/14/2026, 15:57:05 UTC

Last updated: 09/14/2026, 00:26:06 UTC

Views: 97

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses