Hunting for Linux Extended File Attributes
2025-10-21 , Europe

In this lightning talk will show how xattr's can be used to hide a payload, then I'll introduce a quick script that will help to find potentially malicious xattr's on a filesystem.


In this lightning talk will show how xattr's can be used to hide a payload, then I'll introduce a quick script that will help to find potentially malicious xattr's on a filesystem.

Xavier Mertens is a freelance security consultant running his own company based in Belgium (Xameco). With 15+ years of experience in information security, Xavier finds “blue team” activities more attractive. Therefore, his day job focuses on protecting his customers' assets by providing services like incident handling, malware analysis, forensic investigations, log management, security visualization, and OSINT). Besides his day job, Xavier is also a Senior Handler at the SANS Internet Storm Center, Certified SANS Instructor (FOR610, FOR710), security blogger and co-organizer of the BruCON security conference.

This speaker also appears in: