Linux LD_PRELOAD Injection via Cmdline or ld.so.preload (T1574.006)

Detects potential dynamic linker hijacking on Linux systems by monitoring for the use of non-standard LD_PRELOAD paths in process command lines or unauthorized modifications to the /etc/ld.so.preload configuration file, which can be used to inject malicious code into processes.