How can i hooking with seccomp?

308 Views Asked by At

I'm looking for a way to perform Hooking with seccomp or seccomp-bpf.

I want to set a rule so that when a syscall is performed (eg read) I can change the process or the answer that comes back from Syscall. And I must use seccomp.

Tnx

1

There are 1 best solutions below

0
Anthea Chen On

I think what you want is to modify the struct seccomp_data, however, this is a read-only struct.

To bypass this restriction you can use BPF jointly with ptrace, filter syscalls with BPF and modify them using ptrace.