AI-Powered Application Penetration Testing—Scale Security Without Compromise Learn More

Open-Source Linux Process Injection Tool

asminject.py

asminject.py AI open-source Linux process code injection tool by Bishop Fox.

Inject code into trusted Linux processes — without tripping the defenses watching for it.

asminject.py is a code injection tool that compromises Linux-trusted processes and containers.

About asminject.py

Compromise trusted processes with code injection to capture sensitive data.

Protecting software and sensitive data from theft or misuse is unlikely to succeed if attackers gain administrative or physical access to devices that process information in unencrypted form - even for a fraction of a second. We've created asminject.py, a tool that demonstrates an attack on Linux processes and containers using compromised administrative access to the host. Asminject.py was inspired by an environment where container-level endpoint security was part of a larger strategy to protect information within the containers from users with administrator access to the Linux systems that hosted the containers.

Use asminject.py to tamper with trusted processes by injecting arbitrary code via the Linux process filesystem (procfs) interface to capture sensitive data. Without intrusive monitoring at the host level, asminject.py keeps compromise attempts under the radar with minimal detection or response from existing defenses.

See asminject.py in action

Lead Security Researcher

Ben Lincoln

Ben Lincoln, Managing Senior Security Consultant Bishop Fox, headshot.

Ben Lincoln
Managing Principal

Ben Lincoln is a Managing Principal at Bishop Fox and focuses on application security. He has extensive experience in network penetration testing, red team activities, white-/black-box web/native application penetration testing, and exploit development. Prior to joining Bishop Fox, Ben was a security consultant with NCC Group, a global information assurance consulting organization. He also previously worked at a major retail corporation as a senior security engineer and a senior systems engineer. Ben delivered presentations at major security conferences, including "A Black Path Toward the Sun" at Black Hat USA 2016. Ben is OSCP-certified and has released several open-source exploit tools.

asminject.py Research

Check out these related resources

Guide

How to Compromise Trusted Linux Processes and Containers with asminject.py

Dark black background with colored lines with tones of red, grey, teal and white.

This step-by-step technical guide highlights the capabilities of asminject.py, a code injection tool used to compromise Linux processes and containers.

Workshop

A Deep Dive into asminject.py

Dark black background with colored lines in tones of red, grey, and teal and white with lines of code superimposed.

Watch as we explore Bishop Fox asminject.py, a code injection tool that tampers with trusted Linux processes to capture data and change program behavior.

Join the asminject.py Community

asminject.py is open source and built for the offensive security community. Star the repo, file issues, contribute templates, or fork it for your own research.

asminject.py AI open-source Linux process code injection tool by Bishop Fox.

This site uses cookies to provide you with a great user experience. By continuing to use our website, you consent to the use of cookies. To find out more about the cookies we use, please see our Privacy Policy.