mirror of
https://github.com/elastic/detection-rules
synced 2026-06-08 14:00:08 +00:00
[Rule Tuning] Linux DR BBR Tuning (#5514)
* [Rule Tuning] Linux DR BBR Tuning
* Update discovery_getconf_execution.toml
* Fix typo in process.args for dscl command
* Update persistence_web_server_sus_file_creation.toml
---------
Co-authored-by: Colson Wilhoit <48036388+DefSecSentinel@users.noreply.github.com>
(cherry picked from commit 38e2e4766f)
This commit is contained in:
committed by
tradebot-elastic
parent
8d4d99d7f4
commit
363ea285b0
+4
-10
@@ -2,18 +2,16 @@
|
||||
creation_date = "2023/08/24"
|
||||
integration = ["endpoint", "auditd_manager"]
|
||||
maturity = "production"
|
||||
updated_date = "2024/05/21"
|
||||
updated_date = "2024/12/24"
|
||||
|
||||
[rule]
|
||||
author = ["Elastic"]
|
||||
building_block_type = "default"
|
||||
description = """
|
||||
Identify instances where adversaries include trailing space characters to mimic regular files, disguising their activity
|
||||
to evade default file handling mechanisms.
|
||||
"""
|
||||
from = "now-119m"
|
||||
from = "now-9m"
|
||||
index = ["logs-endpoint.events.*", "endgame-*", "auditbeat-*", "logs-auditd_manager.auditd-*"]
|
||||
interval = "60m"
|
||||
language = "eql"
|
||||
license = "Elastic License v2"
|
||||
name = "Processes with Trailing Spaces"
|
||||
@@ -26,35 +24,31 @@ tags = [
|
||||
"OS: macOS",
|
||||
"Use Case: Threat Detection",
|
||||
"Tactic: Defense Evasion",
|
||||
"Rule Type: BBR",
|
||||
"Data Source: Elastic Defend",
|
||||
"Data Source: Elastic Endgame",
|
||||
"Data Source: Auditd Manager",
|
||||
]
|
||||
timestamp_override = "event.ingested"
|
||||
type = "eql"
|
||||
|
||||
query = '''
|
||||
process where event.type == "start" and event.action in ("exec", "exec_event", "executed", "process_started") and
|
||||
process.name : "* "
|
||||
'''
|
||||
|
||||
|
||||
[[rule.threat]]
|
||||
framework = "MITRE ATT&CK"
|
||||
|
||||
[[rule.threat.technique]]
|
||||
id = "T1036"
|
||||
name = "Masquerading"
|
||||
reference = "https://attack.mitre.org/techniques/T1036/"
|
||||
|
||||
[[rule.threat.technique.subtechnique]]
|
||||
id = "T1036.006"
|
||||
name = "Space after Filename"
|
||||
reference = "https://attack.mitre.org/techniques/T1036/006/"
|
||||
|
||||
|
||||
|
||||
[rule.threat.tactic]
|
||||
id = "TA0005"
|
||||
name = "Defense Evasion"
|
||||
reference = "https://attack.mitre.org/tactics/TA0005/"
|
||||
|
||||
+4
-10
@@ -2,18 +2,16 @@
|
||||
creation_date = "2023/08/24"
|
||||
integration = ["endpoint", "auditd_manager"]
|
||||
maturity = "production"
|
||||
updated_date = "2024/05/21"
|
||||
updated_date = "2025/12/24"
|
||||
|
||||
[rule]
|
||||
author = ["Elastic"]
|
||||
building_block_type = "default"
|
||||
description = """
|
||||
Identify activity related where adversaries can include a trap command which then allows programs and shells to specify
|
||||
commands that will be executed upon receiving interrupt signals.
|
||||
"""
|
||||
from = "now-119m"
|
||||
from = "now-9m"
|
||||
index = ["logs-endpoint.events.*", "endgame-*", "auditbeat-*", "logs-auditd_manager.auditd-*"]
|
||||
interval = "60m"
|
||||
language = "eql"
|
||||
license = "Elastic License v2"
|
||||
name = "Trap Signals Execution"
|
||||
@@ -26,35 +24,31 @@ tags = [
|
||||
"OS: macOS",
|
||||
"Use Case: Threat Detection",
|
||||
"Tactic: Privilege Escalation",
|
||||
"Rule Type: BBR",
|
||||
"Data Source: Elastic Defend",
|
||||
"Data Source: Elastic Endgame",
|
||||
"Data Source: Auditd Manager",
|
||||
]
|
||||
timestamp_override = "event.ingested"
|
||||
type = "eql"
|
||||
|
||||
query = '''
|
||||
process where event.type == "start" and event.action in ("exec", "exec_event", "executed", "process_started") and
|
||||
process.name == "trap" and process.args : "SIG*"
|
||||
'''
|
||||
|
||||
|
||||
[[rule.threat]]
|
||||
framework = "MITRE ATT&CK"
|
||||
|
||||
[[rule.threat.technique]]
|
||||
id = "T1546"
|
||||
name = "Event Triggered Execution"
|
||||
reference = "https://attack.mitre.org/techniques/T1546/"
|
||||
|
||||
[[rule.threat.technique.subtechnique]]
|
||||
id = "T1546.005"
|
||||
name = "Trap"
|
||||
reference = "https://attack.mitre.org/techniques/T1546/005/"
|
||||
|
||||
|
||||
|
||||
[rule.threat.tactic]
|
||||
id = "TA0004"
|
||||
name = "Privilege Escalation"
|
||||
reference = "https://attack.mitre.org/tactics/TA0004/"
|
||||
|
||||
@@ -2,7 +2,7 @@
|
||||
creation_date = "2023/07/10"
|
||||
integration = ["endpoint"]
|
||||
maturity = "production"
|
||||
updated_date = "2025/02/03"
|
||||
updated_date = "2025/12/24"
|
||||
|
||||
[transform]
|
||||
[[transform.osquery]]
|
||||
@@ -29,7 +29,6 @@ query = "SELECT pid, username, name FROM processes p JOIN users u ON u.uid = p.u
|
||||
label = "Osquery - Retrieve Process Info"
|
||||
query = "SELECT name, cmdline, parent, path, uid FROM processes"
|
||||
|
||||
|
||||
[rule]
|
||||
author = ["Elastic"]
|
||||
building_block_type = "default"
|
||||
@@ -43,10 +42,10 @@ index = ["logs-endpoint.events.*", "endgame-*"]
|
||||
interval = "60m"
|
||||
language = "eql"
|
||||
license = "Elastic License v2"
|
||||
name = "Potential Non-Standard Port HTTP/HTTPS connection"
|
||||
name = "Deprecated - Potential Non-Standard Port HTTP/HTTPS connection"
|
||||
note = """## Triage and analysis
|
||||
|
||||
### Investigating Potential Non-Standard Port HTTP/HTTPS connection
|
||||
### Investigating Deprecated - Potential Non-Standard Port HTTP/HTTPS connection
|
||||
|
||||
Attackers may alter standard protocol ports, like using HTTP on port 8443 instead of 80, to bypass network filtering and complicate network data analysis.
|
||||
|
||||
@@ -118,26 +117,25 @@ tags = [
|
||||
]
|
||||
timestamp_override = "event.ingested"
|
||||
type = "eql"
|
||||
|
||||
query = '''
|
||||
network where process.name : ("http", "https") and destination.port not in (80, 443) and event.action in (
|
||||
"connection_attempted", "ipv4_connection_attempt_event", "connection_accepted", "ipv4_connection_accept_event"
|
||||
) and destination.ip != "127.0.0.1"
|
||||
'''
|
||||
|
||||
|
||||
[[rule.threat]]
|
||||
framework = "MITRE ATT&CK"
|
||||
|
||||
[[rule.threat.technique]]
|
||||
id = "T1071"
|
||||
name = "Application Layer Protocol"
|
||||
reference = "https://attack.mitre.org/techniques/T1071/"
|
||||
|
||||
[[rule.threat.technique.subtechnique]]
|
||||
id = "T1071.001"
|
||||
name = "Web Protocols"
|
||||
reference = "https://attack.mitre.org/techniques/T1071/001/"
|
||||
|
||||
|
||||
[[rule.threat.technique]]
|
||||
id = "T1571"
|
||||
name = "Non-Standard Port"
|
||||
@@ -147,6 +145,7 @@ reference = "https://attack.mitre.org/techniques/T1571/"
|
||||
id = "T1573"
|
||||
name = "Encrypted Channel"
|
||||
reference = "https://attack.mitre.org/techniques/T1573/"
|
||||
|
||||
[[rule.threat.technique.subtechnique]]
|
||||
id = "T1573.001"
|
||||
name = "Symmetric Cryptography"
|
||||
@@ -157,10 +156,7 @@ id = "T1573.002"
|
||||
name = "Asymmetric Cryptography"
|
||||
reference = "https://attack.mitre.org/techniques/T1573/002/"
|
||||
|
||||
|
||||
|
||||
[rule.threat.tactic]
|
||||
id = "TA0011"
|
||||
name = "Command and Control"
|
||||
reference = "https://attack.mitre.org/tactics/TA0011/"
|
||||
|
||||
|
||||
@@ -1,9 +1,8 @@
|
||||
[metadata]
|
||||
bypass_bbr_timing = true
|
||||
creation_date = "2024/01/10"
|
||||
integration = ["endpoint"]
|
||||
maturity = "production"
|
||||
updated_date = "2024/11/07"
|
||||
updated_date = "2024/12/24"
|
||||
|
||||
[rule]
|
||||
author = ["Elastic"]
|
||||
@@ -16,8 +15,9 @@ types and contents. The CAP_NET_RAW capability allows the process to bind to any
|
||||
namespaces, which allows network traffic sniffing by a non root user. The rule identifies previously unknown processes
|
||||
executing with CAP_NET_RAW capabilities through the use of the new terms rule type.
|
||||
"""
|
||||
from = "now-9m"
|
||||
from = "now-119m"
|
||||
index = ["logs-endpoint.events.*"]
|
||||
interval = "60m"
|
||||
language = "kuery"
|
||||
license = "Elastic License v2"
|
||||
name = "Network Traffic Capture via CAP_NET_RAW"
|
||||
@@ -66,15 +66,14 @@ event.category:"process" and host.os.type:"linux" and event.type:"start" and eve
|
||||
not user.id:"0"
|
||||
'''
|
||||
|
||||
|
||||
[[rule.threat]]
|
||||
framework = "MITRE ATT&CK"
|
||||
|
||||
[[rule.threat.technique]]
|
||||
id = "T1040"
|
||||
name = "Network Sniffing"
|
||||
reference = "https://attack.mitre.org/techniques/T1040/"
|
||||
|
||||
|
||||
[rule.threat.tactic]
|
||||
id = "TA0007"
|
||||
name = "Discovery"
|
||||
@@ -83,8 +82,7 @@ reference = "https://attack.mitre.org/tactics/TA0007/"
|
||||
[rule.new_terms]
|
||||
field = "new_terms_fields"
|
||||
value = ["process.executable"]
|
||||
|
||||
[[rule.new_terms.history_window_start]]
|
||||
field = "history_window_start"
|
||||
value = "now-14d"
|
||||
|
||||
|
||||
value = "now-5d"
|
||||
|
||||
@@ -1,27 +1,21 @@
|
||||
[metadata]
|
||||
creation_date = "2025/01/07"
|
||||
integration = ["endpoint", "auditd_manager", "crowdstrike"]
|
||||
integration = ["endpoint"]
|
||||
maturity = "production"
|
||||
updated_date = "2025/10/17"
|
||||
updated_date = "2025/12/24"
|
||||
|
||||
[rule]
|
||||
author = ["Elastic"]
|
||||
building_block_type = "default"
|
||||
description = """
|
||||
This rule identifies Linux system information discovery via the `getconf` command. The `getconf` command is used to query system configuration
|
||||
This rule identifies Linux system information discovery via the "getconf" command. The "getconf" command is used to query system configuration
|
||||
variables and system limits. Adversaries may use this command to gather information about the system, such as the page size, maximum number
|
||||
of open files, and other system limits, to aid in further exploration and exploitation of the system.
|
||||
"""
|
||||
from = "now-119m"
|
||||
index = [
|
||||
"logs-endpoint.events.process*",
|
||||
"endgame-*",
|
||||
"auditbeat-*",
|
||||
"logs-auditd_manager.auditd-*",
|
||||
"logs-crowdstrike.fdr*",
|
||||
]
|
||||
index = ["logs-endpoint.events.process*"]
|
||||
interval = "60m"
|
||||
language = "eql"
|
||||
language = "kuery"
|
||||
license = "Elastic License v2"
|
||||
name = "Linux System Information Discovery via Getconf"
|
||||
references = ["https://blog.exatrack.com/Perfctl-using-portainer-and-new-persistences/"]
|
||||
@@ -35,15 +29,27 @@ tags = [
|
||||
"Tactic: Discovery",
|
||||
"Rule Type: BBR",
|
||||
"Data Source: Elastic Defend",
|
||||
"Data Source: Elastic Endgame",
|
||||
"Data Source: Auditd Manager",
|
||||
"Data Source: Crowdstrike",
|
||||
]
|
||||
timestamp_override = "event.ingested"
|
||||
type = "eql"
|
||||
type = "new_terms"
|
||||
query = '''
|
||||
process where host.os.type == "linux" and event.type == "start" and event.action in ("exec", "exec_event", "executed", "process_started", "ProcessRollup2") and
|
||||
process.name == "getconf"
|
||||
event.category:process and host.os.type:linux and event.type:start and event.action:exec and process.name:getconf and not (
|
||||
process.parent.executable:(
|
||||
"/usr/bin/google_guest_agent_manager" or "/opt/commvault/Base64/cvlaunchd" or /usr/local/manageengine/uems_agent/bin/*
|
||||
) or
|
||||
process.working_directory:(
|
||||
"/opt/oracle/mgmt_agent/agent_inst/bin" or "/var/lib/oracle-cloud-agent/plugins/oci-managementagent/polaris" or
|
||||
"/opt/commvault/Base/cvlaunchd" or "/opt/simpana" or "/opt/commvault" or "/opt/ITSPlatform/agentcore" or
|
||||
"/u01/app/oracle/EMBase/agent_inst/sysman/emd" or "/opt/abacus/lib"
|
||||
) or
|
||||
process.parent.args:(
|
||||
/opt/oracle/mgmt_agent/agent_inst/* or "/opt/datadog-agent/bin/agent/agent" or "/usr/bin/byobu-status" or
|
||||
"/usr/local/nagios/libexec/check_ssl_cert" or "/usr/lib64/nagios/plugins/cpanel/check_ssl_cert"
|
||||
) or
|
||||
process.parent.command_line:(
|
||||
"/bin/sh -s unix:cmd" or "ruby /usr/local/bundle/bin/bundle exec rackup"
|
||||
)
|
||||
)
|
||||
'''
|
||||
|
||||
[[rule.threat]]
|
||||
@@ -58,3 +64,11 @@ reference = "https://attack.mitre.org/techniques/T1082/"
|
||||
id = "TA0007"
|
||||
name = "Discovery"
|
||||
reference = "https://attack.mitre.org/tactics/TA0007/"
|
||||
|
||||
[rule.new_terms]
|
||||
field = "new_terms_fields"
|
||||
value = ["process.parent.executable"]
|
||||
|
||||
[[rule.new_terms.history_window_start]]
|
||||
field = "history_window_start"
|
||||
value = "now-5d"
|
||||
|
||||
@@ -2,13 +2,13 @@
|
||||
creation_date = "2023/07/11"
|
||||
integration = ["endpoint", "auditd_manager"]
|
||||
maturity = "production"
|
||||
updated_date = "2024/05/21"
|
||||
updated_date = "2024/12/23"
|
||||
|
||||
[rule]
|
||||
author = ["Elastic"]
|
||||
building_block_type = "default"
|
||||
description = """
|
||||
Identifies the use of built-in tools to read the contents of \\etc\\hosts on a local machine. Attackers may use this data
|
||||
Identifies the use of built-in tools to read the contents of "/etc/hosts" on a local machine. Attackers may use this data
|
||||
to discover remote machines in an environment that may be used for Lateral Movement from the current system.
|
||||
"""
|
||||
from = "now-119m"
|
||||
@@ -33,23 +33,21 @@ tags = [
|
||||
]
|
||||
timestamp_override = "event.ingested"
|
||||
type = "eql"
|
||||
|
||||
query = '''
|
||||
process where event.type == "start" and event.action in ("exec", "exec_event", "executed", "process_started") and
|
||||
process.name in ("vi", "nano", "cat", "more", "less") and process.args == "/etc/hosts"
|
||||
process.name in ("vi", "nano", "cat", "more", "less", "vim", "vim.basic", "emacs") and process.args == "/etc/hosts" and
|
||||
not ?process.working_directory in ("/opt/SolarWinds/Agent/bin/Plugins/SCM", "/opt/cohesityagent/software/crux/bin")
|
||||
'''
|
||||
|
||||
|
||||
[[rule.threat]]
|
||||
framework = "MITRE ATT&CK"
|
||||
|
||||
[[rule.threat.technique]]
|
||||
id = "T1018"
|
||||
name = "Remote System Discovery"
|
||||
reference = "https://attack.mitre.org/techniques/T1018/"
|
||||
|
||||
|
||||
[rule.threat.tactic]
|
||||
id = "TA0007"
|
||||
name = "Discovery"
|
||||
reference = "https://attack.mitre.org/tactics/TA0007/"
|
||||
|
||||
|
||||
@@ -2,7 +2,7 @@
|
||||
creation_date = "2020/04/12"
|
||||
integration = ["auditd_manager"]
|
||||
maturity = "production"
|
||||
updated_date = "2024/10/18"
|
||||
updated_date = "2024/12/24"
|
||||
|
||||
[rule]
|
||||
author = ["Elastic"]
|
||||
@@ -56,7 +56,10 @@ timestamp_override = "event.ingested"
|
||||
type = "new_terms"
|
||||
query = '''
|
||||
host.os.type:linux and event.category:file and event.action:"opened-file" and file.path:"/proc/modules" and
|
||||
not process.name:(python* or chef-client)
|
||||
not (
|
||||
process.name:(python* or chef-client) or
|
||||
process.executable:(/opt/eset/*/esets_eia or /opt/Elastic/Agent/* or "/opt/jfrog/artifactory/app/metadata/bin/jf-metadata")
|
||||
)
|
||||
'''
|
||||
|
||||
[[rule.threat]]
|
||||
@@ -78,4 +81,4 @@ value = ["process.executable"]
|
||||
|
||||
[[rule.new_terms.history_window_start]]
|
||||
field = "history_window_start"
|
||||
value = "now-14d"
|
||||
value = "now-5d"
|
||||
|
||||
@@ -2,7 +2,7 @@
|
||||
creation_date = "2025/06/19"
|
||||
integration = ["endpoint", "auditd_manager", "crowdstrike"]
|
||||
maturity = "production"
|
||||
updated_date = "2025/10/17"
|
||||
updated_date = "2025/12/24"
|
||||
|
||||
[rule]
|
||||
author = ["Elastic"]
|
||||
@@ -14,7 +14,13 @@ such as configmaps. In environments where kubectl is not expected to be used, th
|
||||
activity by an adversary.
|
||||
"""
|
||||
from = "now-119m"
|
||||
index = ["logs-endpoint.events.*", "endgame-*", "auditbeat-*", "logs-auditd_manager.auditd-*", "logs-crowdstrike.fdr*"]
|
||||
index = [
|
||||
"logs-endpoint.events.*",
|
||||
"endgame-*",
|
||||
"auditbeat-*",
|
||||
"logs-auditd_manager.auditd-*",
|
||||
"logs-crowdstrike.fdr*"
|
||||
]
|
||||
interval = "60m"
|
||||
language = "eql"
|
||||
license = "Elastic License v2"
|
||||
@@ -40,7 +46,10 @@ type = "eql"
|
||||
query = '''
|
||||
process where host.os.type == "linux" and event.type == "start" and
|
||||
event.action in ("exec", "exec_event", "executed", "process_started", "ProcessRollup2") and
|
||||
process.name == "kubectl" and process.args in ("get", "describe") and process.args in ("configmap", "configmaps")
|
||||
process.name == "kubectl" and process.args in ("get", "describe") and process.args in ("configmap", "configmaps") and
|
||||
not ?process.parent.args in (
|
||||
"/hooks/schedule_sync_configmap.sh", "/service-fabric/generate-support-bundle.sh", "/hooks/onstartup_sync_configmap.sh"
|
||||
)
|
||||
'''
|
||||
|
||||
[[rule.threat]]
|
||||
|
||||
@@ -2,7 +2,7 @@
|
||||
creation_date = "2023/06/08"
|
||||
integration = ["auditd_manager"]
|
||||
maturity = "production"
|
||||
updated_date = "2024/10/18"
|
||||
updated_date = "2025/12/24"
|
||||
|
||||
[rule]
|
||||
author = ["Elastic"]
|
||||
@@ -56,9 +56,16 @@ type = "new_terms"
|
||||
|
||||
query = '''
|
||||
host.os.type:linux and event.category:file and event.action:"opened-file" and
|
||||
file.path : ("/etc/modprobe.conf" or "/etc/modprobe.d" or /etc/modprobe.d/*) and not process.name:(
|
||||
cp or dpkg or dockerd or lynis or mkinitramfs or snapd or systemd-udevd or borg or auditbeat or lspci or
|
||||
aide or modprobe or python*
|
||||
file.path : ("/etc/modprobe.conf" or "/etc/modprobe.d" or /etc/modprobe.d/*) and
|
||||
not (
|
||||
process.name:(
|
||||
cp or dpkg or dockerd or lynis or mkinitramfs or snapd or systemd-udevd or borg or auditbeat or lspci or
|
||||
aide or modprobe or python*
|
||||
) or
|
||||
process.executable:(
|
||||
/opt/sophos/* or /opt/eset/* or /var/lib/elastic* or /opt/Elastic/* or "/usr/lib/dracut/dracut-install" or
|
||||
"/usr/bin/pacman" or /opt/saltstack/salt/bin/python* or /var/lib/waagent/* or /opt/sophos-spl/plugins/av/bin/*
|
||||
)
|
||||
)
|
||||
'''
|
||||
|
||||
@@ -81,4 +88,4 @@ value = ["process.executable"]
|
||||
|
||||
[[rule.new_terms.history_window_start]]
|
||||
field = "history_window_start"
|
||||
value = "now-14d"
|
||||
value = "now-5d"
|
||||
|
||||
@@ -2,7 +2,7 @@
|
||||
creation_date = "2023/06/08"
|
||||
integration = ["auditd_manager"]
|
||||
maturity = "production"
|
||||
updated_date = "2024/10/18"
|
||||
updated_date = "2025/12/24"
|
||||
|
||||
[rule]
|
||||
author = ["Elastic"]
|
||||
@@ -56,8 +56,13 @@ type = "new_terms"
|
||||
|
||||
query = '''
|
||||
host.os.type:linux and event.category:file and event.action:("opened-file" or "read-file" or "wrote-to-file") and
|
||||
file.path : ("/etc/sysctl.conf" or "/etc/sysctl.d" or /etc/sysctl.d/*) and not process.name:(
|
||||
dpkg or dockerd or unattended-upg or systemd-sysctl or python* or auditbeat or dpkg or pool*
|
||||
file.path : ("/etc/sysctl.conf" or "/etc/sysctl.d" or /etc/sysctl.d/*) and not (
|
||||
process.name:(
|
||||
dpkg or dockerd or unattended-upg or systemd-sysctl or python* or auditbeat or dpkg or pool*
|
||||
) or
|
||||
process.executable:(
|
||||
/opt/sophos-spl/plugins/av/bin/* or /usr/bin/pacman or "/usr/lib/dracut/dracut-install" or /var/lib/elastic-agent/*
|
||||
)
|
||||
)
|
||||
'''
|
||||
|
||||
@@ -80,4 +85,4 @@ value = ["process.executable"]
|
||||
|
||||
[[rule.new_terms.history_window_start]]
|
||||
field = "history_window_start"
|
||||
value = "now-14d"
|
||||
value = "now-5d"
|
||||
|
||||
@@ -1,17 +1,21 @@
|
||||
[metadata]
|
||||
creation_date = "2023/07/10"
|
||||
integration = ["endpoint", "auditd_manager", "crowdstrike"]
|
||||
integration = ["endpoint", "sentinel_one_cloud_funnel"]
|
||||
maturity = "production"
|
||||
updated_date = "2025/10/17"
|
||||
updated_date = "2025/12/24"
|
||||
|
||||
[rule]
|
||||
author = ["Elastic"]
|
||||
building_block_type = "default"
|
||||
description = "Enrich process events with uname and other command lines that imply Linux system information discovery."
|
||||
description = """
|
||||
This rule identifies Linux system information discovery activity via built-in commands that read common
|
||||
system files. Adversaries may use these commands to gather information about the operating system, installed
|
||||
services, and hardware configuration to aid in further exploration and exploitation of the system.
|
||||
"""
|
||||
from = "now-119m"
|
||||
index = ["logs-endpoint.events.*", "endgame-*", "auditbeat-*", "logs-auditd_manager.auditd-*", "logs-crowdstrike.fdr*"]
|
||||
index = ["logs-endpoint.events.*", "endgame-*", "logs-sentinel_one_cloud_funnel.*",]
|
||||
interval = "60m"
|
||||
language = "eql"
|
||||
language = "kuery"
|
||||
license = "Elastic License v2"
|
||||
name = "Linux System Information Discovery"
|
||||
risk_score = 21
|
||||
@@ -25,31 +29,38 @@ tags = [
|
||||
"Rule Type: BBR",
|
||||
"Data Source: Elastic Defend",
|
||||
"Data Source: Elastic Endgame",
|
||||
"Data Source: Auditd Manager",
|
||||
"Data Source: Crowdstrike",
|
||||
"Data Source: SentinelOne",
|
||||
|
||||
]
|
||||
timestamp_override = "event.ingested"
|
||||
type = "eql"
|
||||
|
||||
type = "new_terms"
|
||||
query = '''
|
||||
process where event.type == "start" and event.action in ("exec", "exec_event", "executed", "process_started", "ProcessRollup2") and (
|
||||
process.name: "uname" or (
|
||||
process.name: ("cat", "more", "less") and process.args: ("*issue*", "*version*", "*profile*", "*services*", "*cpuinfo*")
|
||||
)
|
||||
)
|
||||
event.category:process and host.os.type:linux and event.type:start and event.action:(exec or exec_event or start) and
|
||||
process.name:("cat" or "more" or "less" or "nano" or "vi" or "vim" or "vim.basic" or "emacs") and
|
||||
process.args:(
|
||||
"/etc/issue" or "/etc/os-release" or "/proc/version" or "/etc/profile" or "/proc/cpuinfo" or "/etc/services" or
|
||||
"/etc/lsb-release" or "/etc/redhat-release" or "/etc/debian_version" or "/etc/hostname"
|
||||
) and
|
||||
not process.parent.executable:("/usr/local/jamf/bin/jamf" or "/etc/cp/watchdog/cp-nano-watchdog")
|
||||
'''
|
||||
|
||||
|
||||
[[rule.threat]]
|
||||
framework = "MITRE ATT&CK"
|
||||
|
||||
[[rule.threat.technique]]
|
||||
id = "T1082"
|
||||
name = "System Information Discovery"
|
||||
reference = "https://attack.mitre.org/techniques/T1082/"
|
||||
|
||||
|
||||
[rule.threat.tactic]
|
||||
id = "TA0007"
|
||||
name = "Discovery"
|
||||
reference = "https://attack.mitre.org/tactics/TA0007/"
|
||||
|
||||
[rule.new_terms]
|
||||
field = "new_terms_fields"
|
||||
value = ["process.parent.executable", "process.command_line", "agent.id"]
|
||||
|
||||
[[rule.new_terms.history_window_start]]
|
||||
field = "history_window_start"
|
||||
value = "now-5d"
|
||||
|
||||
@@ -1,8 +1,8 @@
|
||||
[metadata]
|
||||
creation_date = "2023/07/10"
|
||||
integration = ["endpoint", "auditd_manager", "crowdstrike"]
|
||||
integration = ["endpoint", "sentinel_one_cloud_funnel"]
|
||||
maturity = "production"
|
||||
updated_date = "2025/10/17"
|
||||
updated_date = "2025/12/24"
|
||||
|
||||
[rule]
|
||||
author = ["Elastic"]
|
||||
@@ -12,9 +12,9 @@ Identifies the use of built-in tools which adversaries may use to enumerate the
|
||||
system.
|
||||
"""
|
||||
from = "now-119m"
|
||||
index = ["logs-endpoint.events.*", "endgame-*", "auditbeat-*", "logs-auditd_manager.auditd-*", "logs-crowdstrike.fdr*"]
|
||||
index = ["logs-endpoint.events.*", "endgame-*", "logs-sentinel_one_cloud_funnel.*",]
|
||||
interval = "60m"
|
||||
language = "eql"
|
||||
language = "kuery"
|
||||
license = "Elastic License v2"
|
||||
name = "System Owner/User Discovery Linux"
|
||||
risk_score = 21
|
||||
@@ -28,20 +28,18 @@ tags = [
|
||||
"Rule Type: BBR",
|
||||
"Data Source: Elastic Defend",
|
||||
"Data Source: Elastic Endgame",
|
||||
"Data Source: Auditd Manager",
|
||||
"Data Source: Crowdstrike",
|
||||
"Data Source: SentinelOne",
|
||||
]
|
||||
timestamp_override = "event.ingested"
|
||||
type = "eql"
|
||||
|
||||
type = "new_terms"
|
||||
query = '''
|
||||
process where event.type == "start" and event.action in ("exec", "exec_event", "executed", "process_started", "ProcessRollup2") and
|
||||
process.name : ("whoami", "w", "who", "users", "id")
|
||||
event.category:process and host.os.type:linux and event.type:start and event.action:(exec or exec_event or start) and
|
||||
process.name:("whoami" or "w" or "who" or "users" or "id" or "groups")
|
||||
'''
|
||||
|
||||
|
||||
[[rule.threat]]
|
||||
framework = "MITRE ATT&CK"
|
||||
|
||||
[[rule.threat.technique]]
|
||||
id = "T1033"
|
||||
name = "System Owner/User Discovery"
|
||||
@@ -52,9 +50,15 @@ id = "T1069"
|
||||
name = "Permission Groups Discovery"
|
||||
reference = "https://attack.mitre.org/techniques/T1069/"
|
||||
|
||||
|
||||
[rule.threat.tactic]
|
||||
id = "TA0007"
|
||||
name = "Discovery"
|
||||
reference = "https://attack.mitre.org/tactics/TA0007/"
|
||||
|
||||
[rule.new_terms]
|
||||
field = "new_terms_fields"
|
||||
value = ["process.parent.executable", "process.command_line", "agent.id"]
|
||||
|
||||
[[rule.new_terms.history_window_start]]
|
||||
field = "history_window_start"
|
||||
value = "now-5d"
|
||||
|
||||
@@ -1,17 +1,19 @@
|
||||
[metadata]
|
||||
creation_date = "2023/07/11"
|
||||
integration = ["endpoint", "auditd_manager"]
|
||||
integration = ["endpoint"]
|
||||
maturity = "production"
|
||||
updated_date = "2024/05/21"
|
||||
updated_date = "2025/12/24"
|
||||
|
||||
[rule]
|
||||
author = ["Elastic"]
|
||||
building_block_type = "default"
|
||||
description = "Adversaries may use built-in applications to get a listing of local system or domain accounts and groups.\n"
|
||||
description = """
|
||||
Adversaries may use built-in applications to get a listing of local system or domain accounts and groups.
|
||||
"""
|
||||
from = "now-119m"
|
||||
index = ["logs-endpoint.events.*", "endgame-*", "auditbeat-*", "logs-auditd_manager.auditd-*"]
|
||||
index = ["logs-endpoint.events.*"]
|
||||
interval = "60m"
|
||||
language = "eql"
|
||||
language = "kuery"
|
||||
license = "Elastic License v2"
|
||||
name = "Account or Group Discovery via Built-In Tools"
|
||||
risk_score = 21
|
||||
@@ -25,29 +27,35 @@ tags = [
|
||||
"Tactic: Discovery",
|
||||
"Rule Type: BBR",
|
||||
"Data Source: Elastic Defend",
|
||||
"Data Source: Elastic Endgame",
|
||||
"Data Source: Auditd Manager",
|
||||
]
|
||||
timestamp_override = "event.ingested"
|
||||
type = "eql"
|
||||
|
||||
type = "new_terms"
|
||||
query = '''
|
||||
process where event.type == "start" and event.action in ("exec", "exec_event", "executed", "process_started") and (
|
||||
(process.name in ("groups", "id")) or
|
||||
(process.name == "dscl" and process.args : ("/Active Directory/*", "/Users*", "/Groups*")) or
|
||||
(process.name == "dscacheutil" and process.args in ("user", "group")) or
|
||||
(process.args in ("/etc/passwd", "/etc/master.passwd", "/etc/sudoers")) or
|
||||
(process.name == "getent" and process.args in ("passwd", "group"))
|
||||
event.category:process and host.os.type:(linux or macos) and event.action:exec and (
|
||||
(process.name:"dscl" and process.args:(/Active*Directory/* or /Users* or /Groups*)) or
|
||||
(process.name:"dscacheutil" and process.args:("user" or "group")) or
|
||||
(process.name:"getent" and process.args:("passwd" or "group") and process.args_count >= 3)
|
||||
) and not (
|
||||
process.parent.executable:(
|
||||
"/usr/lib/ocf/resource.d/cyanconnode/mysql" or /snap/* or "/usr/bin/check_mk_agent" or "/usr/bin/cloudflared" or
|
||||
/opt/puppetlabs/* or /var/lib/snapd/* or "/usr/lib/google/guest_agent/core_plugin" or "/opt/rudder/bin/cf-agent" or
|
||||
"/opt/NinjaRMMAgent/programfiles/ninjarmm-linagent"
|
||||
) or
|
||||
process.working_directory:(
|
||||
/var/snap/* or "/Applications/NinjaRMMAgent/programfiles/ninjarmm-macagent" or "/var/lib/nanitor/agent" or
|
||||
"/var/ossec" or /opt/rapid7/* or "/opt/Tanium/TaniumClient"
|
||||
)
|
||||
)
|
||||
'''
|
||||
|
||||
|
||||
[[rule.threat]]
|
||||
framework = "MITRE ATT&CK"
|
||||
|
||||
[[rule.threat.technique]]
|
||||
id = "T1069"
|
||||
name = "Permission Groups Discovery"
|
||||
reference = "https://attack.mitre.org/techniques/T1069/"
|
||||
|
||||
[[rule.threat.technique.subtechnique]]
|
||||
id = "T1069.001"
|
||||
name = "Local Groups"
|
||||
@@ -58,11 +66,11 @@ id = "T1069.002"
|
||||
name = "Domain Groups"
|
||||
reference = "https://attack.mitre.org/techniques/T1069/002/"
|
||||
|
||||
|
||||
[[rule.threat.technique]]
|
||||
id = "T1087"
|
||||
name = "Account Discovery"
|
||||
reference = "https://attack.mitre.org/techniques/T1087/"
|
||||
|
||||
[[rule.threat.technique.subtechnique]]
|
||||
id = "T1087.001"
|
||||
name = "Local Account"
|
||||
@@ -73,10 +81,15 @@ id = "T1087.002"
|
||||
name = "Domain Account"
|
||||
reference = "https://attack.mitre.org/techniques/T1087/002/"
|
||||
|
||||
|
||||
|
||||
[rule.threat.tactic]
|
||||
id = "TA0007"
|
||||
name = "Discovery"
|
||||
reference = "https://attack.mitre.org/tactics/TA0007/"
|
||||
|
||||
[rule.new_terms]
|
||||
field = "new_terms_fields"
|
||||
value = ["process.parent.executable", "process.command_line", "agent.id"]
|
||||
|
||||
[[rule.new_terms.history_window_start]]
|
||||
field = "history_window_start"
|
||||
value = "now-5d"
|
||||
|
||||
@@ -3,7 +3,7 @@ bypass_bbr_timing = true
|
||||
creation_date = "2024/02/01"
|
||||
integration = ["endpoint"]
|
||||
maturity = "production"
|
||||
updated_date = "2024/10/18"
|
||||
updated_date = "2025/12/24"
|
||||
|
||||
[rule]
|
||||
author = ["Elastic"]
|
||||
@@ -39,14 +39,22 @@ process where host.os.type == "linux" and event.type == "start" and event.action
|
||||
(process.name in ("hexdump", "xxd") and process.args == "-s") or
|
||||
(process.name == "dd" and process.args : ("skip*", "seek*"))
|
||||
) and not (
|
||||
process.parent.args like ("/opt/error_monitor/error_monitor.sh", "printf*") or
|
||||
process.parent.args like ("/opt/error_monitor/error_monitor.sh", "printf*", "/sbin/dracut") or
|
||||
process.parent.name in ("acme.sh", "dracut", "leapp") or
|
||||
process.parent.executable like (
|
||||
"/bin/cagefs_enter", "/opt/nessus_agent/sbin/nessus-service", "/usr/libexec/platform-python*",
|
||||
"/usr/libexec/vdsm/vdsmd", "/usr/local/bin/docker-entrypoint.sh", "/usr/lib/module-init-tools/lsinitrd-quick"
|
||||
"/usr/libexec/vdsm/vdsmd", "/usr/local/bin/docker-entrypoint.sh", "/usr/lib/module-init-tools/lsinitrd-quick",
|
||||
"/usr/bin/unmkinitramfs", "/usr/bin/lsinitramfs", "/opt/msp-agent/msp-agent-core.run",
|
||||
"/usr/local/cloudamize/bin/register.sh", "/usr/local/hestia/bin/v-log-action", "/usr/local/emps/bin/php"
|
||||
) or
|
||||
process.parent.command_line like "sh*acme.sh*" or
|
||||
process.args like "/var/tmp/dracut*"
|
||||
process.args like ("/var/tmp/dracut*", "/opt/bitdefender-security-tools/var/log/script_update.log") or
|
||||
?process.working_directory like (
|
||||
"/usr/local/nutanix/ngt/python/bin", "/var/lib/waagent/*", "/opt/Tychon/Endpoint/bin",
|
||||
"/usr/local/cloudamize/bin", "/opt/sentinelone/bin"
|
||||
) or
|
||||
process.command_line in ("tail -c 1", "tail -c 2") or
|
||||
(process.command_line == "dd ibs=18850 skip=1 count=1" and process.parent.args == "/opt/msp-agent/msp-agent-core.run")
|
||||
)
|
||||
'''
|
||||
|
||||
|
||||
@@ -2,16 +2,18 @@
|
||||
creation_date = "2023/07/11"
|
||||
integration = ["endpoint"]
|
||||
maturity = "production"
|
||||
updated_date = "2024/05/21"
|
||||
updated_date = "2025/12/24"
|
||||
|
||||
[rule]
|
||||
author = ["Elastic"]
|
||||
building_block_type = "default"
|
||||
description = "Identifies the use of built-in tools attackers can use to discover running processes on an endpoint."
|
||||
description = """
|
||||
Identifies the use of built-in tools attackers can use to discover running processes on an endpoint.
|
||||
"""
|
||||
from = "now-119m"
|
||||
index = ["logs-endpoint.events.*", "endgame-*"]
|
||||
interval = "60m"
|
||||
language = "eql"
|
||||
language = "kuery"
|
||||
license = "Elastic License v2"
|
||||
name = "Process Discovery via Built-In Applications"
|
||||
risk_score = 21
|
||||
@@ -28,18 +30,22 @@ tags = [
|
||||
"Data Source: Elastic Endgame",
|
||||
]
|
||||
timestamp_override = "event.ingested"
|
||||
type = "eql"
|
||||
|
||||
type = "new_terms"
|
||||
query = '''
|
||||
process where event.type == "start" and event.action in ("exec", "exec_event") and process.name in (
|
||||
"ps", "pstree", "htop", "pgrep"
|
||||
) and
|
||||
not process.parent.name in ("amazon-ssm-agent", "snap")
|
||||
event.category:process and host.os.type:(linux or macos) and event.type:start and event.action:(exec or exec_event) and
|
||||
process.name:("ps" or "pstree" or "htop" or "pgrep") and not (
|
||||
process.parent.name:("amazon-ssm-agent" or "snap") or
|
||||
process.parent.args:("/usr/local/ASR/Vx/bin/status" or "/usr/sbin/ksmtuned") or
|
||||
process.parent.executable:(
|
||||
"/usr/bin/check_mk_agent" or /opt/gitlab/* or "/usr/bin/pmlogctl" or "/usr/libexec/pcp/bin/pmlogger_daily" or
|
||||
"/usr/libexec/pcp/bin/pmlogger_check"
|
||||
)
|
||||
)
|
||||
'''
|
||||
|
||||
|
||||
[[rule.threat]]
|
||||
framework = "MITRE ATT&CK"
|
||||
|
||||
[[rule.threat.technique]]
|
||||
id = "T1057"
|
||||
name = "Process Discovery"
|
||||
@@ -49,15 +55,21 @@ reference = "https://attack.mitre.org/techniques/T1057/"
|
||||
id = "T1518"
|
||||
name = "Software Discovery"
|
||||
reference = "https://attack.mitre.org/techniques/T1518/"
|
||||
|
||||
[[rule.threat.technique.subtechnique]]
|
||||
id = "T1518.001"
|
||||
name = "Security Software Discovery"
|
||||
reference = "https://attack.mitre.org/techniques/T1518/001/"
|
||||
|
||||
|
||||
|
||||
[rule.threat.tactic]
|
||||
id = "TA0007"
|
||||
name = "Discovery"
|
||||
reference = "https://attack.mitre.org/tactics/TA0007/"
|
||||
|
||||
[rule.new_terms]
|
||||
field = "new_terms_fields"
|
||||
value = ["process.parent.executable", "process.command_line", "agent.id"]
|
||||
|
||||
[[rule.new_terms.history_window_start]]
|
||||
field = "history_window_start"
|
||||
value = "now-5d"
|
||||
|
||||
@@ -1,17 +1,19 @@
|
||||
[metadata]
|
||||
creation_date = "2023/07/11"
|
||||
integration = ["endpoint", "auditd_manager"]
|
||||
integration = ["endpoint"]
|
||||
maturity = "production"
|
||||
updated_date = "2024/05/21"
|
||||
updated_date = "2025/12/24"
|
||||
|
||||
[rule]
|
||||
author = ["Elastic"]
|
||||
building_block_type = "default"
|
||||
description = "Adversaries may attempt to get a listing of network connections to or from a compromised system."
|
||||
description = """
|
||||
Adversaries may attempt to get a listing of network connections to or from a compromised system.
|
||||
"""
|
||||
from = "now-119m"
|
||||
index = ["logs-endpoint.events.*", "endgame-*", "auditbeat-*", "logs-auditd_manager.auditd-*"]
|
||||
index = ["logs-endpoint.events.*"]
|
||||
interval = "60m"
|
||||
language = "eql"
|
||||
language = "kuery"
|
||||
license = "Elastic License v2"
|
||||
name = "System Network Connections Discovery"
|
||||
risk_score = 21
|
||||
@@ -25,28 +27,38 @@ tags = [
|
||||
"Tactic: Discovery",
|
||||
"Rule Type: BBR",
|
||||
"Data Source: Elastic Defend",
|
||||
"Data Source: Elastic Endgame",
|
||||
"Data Source: Auditd Manager",
|
||||
]
|
||||
timestamp_override = "event.ingested"
|
||||
type = "eql"
|
||||
|
||||
type = "new_terms"
|
||||
query = '''
|
||||
process where event.type == "start" and event.action in ("exec", "exec_event", "executed", "process_started") and
|
||||
process.name in ("netstat", "lsof", "who", "w")
|
||||
event.category:process and host.os.type:(linux or macos) and event.type:start and event.action:exec and
|
||||
process.name:("netstat" or "lsof" or "ss" or "iftop" or "ip" or "nmcli" or "arp" or "route" or "ifconfig" or "netcfg" or "networksetup") and
|
||||
not (
|
||||
process.parent.executable:(
|
||||
/Library/Elastic/Agent/* or "/Applications/Docker.app/Contents/MacOS/com.docker.backend" or
|
||||
"/opt/NinjaRMMAgent/programfiles/ninjarmm-linagent" or "/usr/local/ASR/Vx/bin/svagents"
|
||||
) or
|
||||
process.working_directory:("/var/ossec" or "/usr/lib/check_mk_agent/plugins" or "/opt/microsoft/mdatp/sbin")
|
||||
)
|
||||
'''
|
||||
|
||||
|
||||
[[rule.threat]]
|
||||
framework = "MITRE ATT&CK"
|
||||
|
||||
[[rule.threat.technique]]
|
||||
id = "T1049"
|
||||
name = "System Network Connections Discovery"
|
||||
reference = "https://attack.mitre.org/techniques/T1049/"
|
||||
|
||||
|
||||
[rule.threat.tactic]
|
||||
id = "TA0007"
|
||||
name = "Discovery"
|
||||
reference = "https://attack.mitre.org/tactics/TA0007/"
|
||||
|
||||
[rule.new_terms]
|
||||
field = "new_terms_fields"
|
||||
value = ["process.parent.executable", "process.command_line", "agent.id"]
|
||||
|
||||
[[rule.new_terms.history_window_start]]
|
||||
field = "history_window_start"
|
||||
value = "now-5d"
|
||||
|
||||
@@ -3,7 +3,7 @@ bypass_bbr_timing = true
|
||||
creation_date = "2023/10/11"
|
||||
integration = ["github"]
|
||||
maturity = "production"
|
||||
updated_date = "2025/03/20"
|
||||
updated_date = "2025/12/24"
|
||||
|
||||
[rule]
|
||||
author = ["Elastic"]
|
||||
@@ -53,6 +53,6 @@ field = "new_terms_fields"
|
||||
value = ["github.hashed_token", "event.action"]
|
||||
[[rule.new_terms.history_window_start]]
|
||||
field = "history_window_start"
|
||||
value = "now-14d"
|
||||
value = "now-5d"
|
||||
|
||||
|
||||
|
||||
@@ -3,7 +3,7 @@ bypass_bbr_timing = true
|
||||
creation_date = "2023/10/11"
|
||||
integration = ["github"]
|
||||
maturity = "production"
|
||||
updated_date = "2025/03/20"
|
||||
updated_date = "2025/12/24"
|
||||
|
||||
[rule]
|
||||
author = ["Elastic"]
|
||||
@@ -54,6 +54,6 @@ field = "new_terms_fields"
|
||||
value = ["github.hashed_token", "github.repo"]
|
||||
[[rule.new_terms.history_window_start]]
|
||||
field = "history_window_start"
|
||||
value = "now-14d"
|
||||
value = "now-5d"
|
||||
|
||||
|
||||
|
||||
@@ -3,7 +3,7 @@ bypass_bbr_timing = true
|
||||
creation_date = "2023/10/11"
|
||||
integration = ["github"]
|
||||
maturity = "production"
|
||||
updated_date = "2025/03/20"
|
||||
updated_date = "2025/12/24"
|
||||
|
||||
[rule]
|
||||
author = ["Elastic"]
|
||||
@@ -53,6 +53,6 @@ field = "new_terms_fields"
|
||||
value = ["user.name", "github.repo"]
|
||||
[[rule.new_terms.history_window_start]]
|
||||
field = "history_window_start"
|
||||
value = "now-14d"
|
||||
value = "now-5d"
|
||||
|
||||
|
||||
|
||||
@@ -3,7 +3,7 @@ bypass_bbr_timing = true
|
||||
creation_date = "2023/10/11"
|
||||
integration = ["github"]
|
||||
maturity = "production"
|
||||
updated_date = "2025/03/20"
|
||||
updated_date = "2025/12/24"
|
||||
|
||||
[rule]
|
||||
author = ["Elastic"]
|
||||
@@ -53,6 +53,6 @@ field = "new_terms_fields"
|
||||
value = ["github.repo", "github.actor_ip"]
|
||||
[[rule.new_terms.history_window_start]]
|
||||
field = "history_window_start"
|
||||
value = "now-14d"
|
||||
value = "now-5d"
|
||||
|
||||
|
||||
|
||||
@@ -3,7 +3,7 @@ bypass_bbr_timing = true
|
||||
creation_date = "2023/10/11"
|
||||
integration = ["github"]
|
||||
maturity = "production"
|
||||
updated_date = "2025/03/20"
|
||||
updated_date = "2025/12/24"
|
||||
|
||||
[rule]
|
||||
author = ["Elastic"]
|
||||
@@ -58,6 +58,6 @@ field = "new_terms_fields"
|
||||
value = ["github.hashed_token", "github.actor_ip"]
|
||||
[[rule.new_terms.history_window_start]]
|
||||
field = "history_window_start"
|
||||
value = "now-14d"
|
||||
value = "now-5d"
|
||||
|
||||
|
||||
|
||||
@@ -3,7 +3,7 @@ bypass_bbr_timing = true
|
||||
creation_date = "2023/10/11"
|
||||
integration = ["github"]
|
||||
maturity = "production"
|
||||
updated_date = "2025/03/20"
|
||||
updated_date = "2025/12/24"
|
||||
|
||||
[rule]
|
||||
author = ["Elastic"]
|
||||
@@ -57,6 +57,6 @@ field = "new_terms_fields"
|
||||
value = ["user.name", "github.actor_ip"]
|
||||
[[rule.new_terms.history_window_start]]
|
||||
field = "history_window_start"
|
||||
value = "now-14d"
|
||||
value = "now-5d"
|
||||
|
||||
|
||||
|
||||
@@ -3,7 +3,7 @@ bypass_bbr_timing = true
|
||||
creation_date = "2023/10/11"
|
||||
integration = ["github"]
|
||||
maturity = "production"
|
||||
updated_date = "2025/03/20"
|
||||
updated_date = "2025/12/24"
|
||||
|
||||
[rule]
|
||||
author = ["Elastic"]
|
||||
@@ -58,6 +58,6 @@ field = "new_terms_fields"
|
||||
value = ["github.hashed_token", "github.user_agent"]
|
||||
[[rule.new_terms.history_window_start]]
|
||||
field = "history_window_start"
|
||||
value = "now-14d"
|
||||
value = "now-5d"
|
||||
|
||||
|
||||
|
||||
@@ -3,7 +3,7 @@ bypass_bbr_timing = true
|
||||
creation_date = "2023/10/11"
|
||||
integration = ["github"]
|
||||
maturity = "production"
|
||||
updated_date = "2025/03/20"
|
||||
updated_date = "2025/12/24"
|
||||
|
||||
[rule]
|
||||
author = ["Elastic"]
|
||||
@@ -57,6 +57,6 @@ field = "new_terms_fields"
|
||||
value = ["user.name", "github.user_agent"]
|
||||
[[rule.new_terms.history_window_start]]
|
||||
field = "history_window_start"
|
||||
value = "now-14d"
|
||||
value = "now-5d"
|
||||
|
||||
|
||||
|
||||
@@ -3,7 +3,7 @@ bypass_bbr_timing = true
|
||||
creation_date = "2024/01/10"
|
||||
integration = ["endpoint"]
|
||||
maturity = "production"
|
||||
updated_date = "2024/11/07"
|
||||
updated_date = "2025/12/24"
|
||||
|
||||
[rule]
|
||||
author = ["Elastic"]
|
||||
@@ -19,7 +19,7 @@ from = "now-9m"
|
||||
index = ["logs-endpoint.events.*"]
|
||||
language = "kuery"
|
||||
license = "Elastic License v2"
|
||||
name = "CAP_SYS_ADMIN Assigned to Binary"
|
||||
name = "Deprecated - CAP_SYS_ADMIN Assigned to Binary"
|
||||
risk_score = 21
|
||||
rule_id = "a577e524-c2ee-47bd-9c5b-e917d01d3276"
|
||||
setup = """## Setup
|
||||
@@ -59,14 +59,12 @@ tags = [
|
||||
]
|
||||
timestamp_override = "event.ingested"
|
||||
type = "new_terms"
|
||||
|
||||
query = '''
|
||||
event.category:"process" and host.os.type:"linux" and event.type:"start" and event.action:"exec" and process.name:* and
|
||||
(process.thread.capabilities.effective:"CAP_SYS_ADMIN" or process.thread.capabilities.permitted:"CAP_SYS_ADMIN") and
|
||||
not user.id:"0"
|
||||
'''
|
||||
|
||||
|
||||
[[rule.threat]]
|
||||
framework = "MITRE ATT&CK"
|
||||
|
||||
@@ -77,9 +75,8 @@ reference = "https://attack.mitre.org/tactics/TA0003/"
|
||||
|
||||
[rule.new_terms]
|
||||
field = "new_terms_fields"
|
||||
value = ["host.id", "user.id", "process.executable"]
|
||||
value = ["agent.id", "user.id", "process.executable"]
|
||||
|
||||
[[rule.new_terms.history_window_start]]
|
||||
field = "history_window_start"
|
||||
value = "now-14d"
|
||||
|
||||
|
||||
value = "now-5d"
|
||||
|
||||
@@ -2,7 +2,7 @@
|
||||
creation_date = "2023/08/23"
|
||||
integration = ["endpoint"]
|
||||
maturity = "production"
|
||||
updated_date = "2024/05/21"
|
||||
updated_date = "2025/12/24"
|
||||
|
||||
[rule]
|
||||
author = ["Elastic"]
|
||||
@@ -13,7 +13,7 @@ index = ["logs-endpoint.events.*", "endgame-*"]
|
||||
interval = "60m"
|
||||
language = "eql"
|
||||
license = "Elastic License v2"
|
||||
name = "Creation of Kernel Module"
|
||||
name = "Deprecated - Creation of Kernel Module"
|
||||
risk_score = 21
|
||||
rule_id = "947827c6-9ed6-4dec-903e-c856c86e72f3"
|
||||
severity = "low"
|
||||
@@ -28,7 +28,6 @@ tags = [
|
||||
]
|
||||
timestamp_override = "event.ingested"
|
||||
type = "eql"
|
||||
|
||||
query = '''
|
||||
file where host.os.type == "linux" and event.type in ("change", "creation") and file.path : "/lib/modules/*" and
|
||||
file.extension == "ko" and not process.name : (
|
||||
@@ -36,22 +35,20 @@ file.extension == "ko" and not process.name : (
|
||||
)
|
||||
'''
|
||||
|
||||
|
||||
[[rule.threat]]
|
||||
framework = "MITRE ATT&CK"
|
||||
|
||||
[[rule.threat.technique]]
|
||||
id = "T1547"
|
||||
name = "Boot or Logon Autostart Execution"
|
||||
reference = "https://attack.mitre.org/techniques/T1547/"
|
||||
|
||||
[[rule.threat.technique.subtechnique]]
|
||||
id = "T1547.006"
|
||||
name = "Kernel Modules and Extensions"
|
||||
reference = "https://attack.mitre.org/techniques/T1547/006/"
|
||||
|
||||
|
||||
|
||||
[rule.threat.tactic]
|
||||
id = "TA0003"
|
||||
name = "Persistence"
|
||||
reference = "https://attack.mitre.org/tactics/TA0003/"
|
||||
|
||||
|
||||
@@ -3,7 +3,7 @@ bypass_bbr_timing = true
|
||||
creation_date = "2023/10/11"
|
||||
integration = ["github"]
|
||||
maturity = "production"
|
||||
updated_date = "2025/03/20"
|
||||
updated_date = "2025/12/24"
|
||||
|
||||
[rule]
|
||||
author = ["Elastic"]
|
||||
@@ -58,6 +58,6 @@ field = "new_terms_fields"
|
||||
value = ["user.name", "github.hashed_token"]
|
||||
[[rule.new_terms.history_window_start]]
|
||||
field = "history_window_start"
|
||||
value = "now-14d"
|
||||
value = "now-5d"
|
||||
|
||||
|
||||
|
||||
@@ -3,7 +3,7 @@ bypass_bbr_timing = true
|
||||
creation_date = "2025/03/06"
|
||||
integration = ["endpoint"]
|
||||
maturity = "production"
|
||||
updated_date = "2025/07/16"
|
||||
updated_date = "2025/12/24"
|
||||
|
||||
[rule]
|
||||
author = ["Elastic"]
|
||||
@@ -19,7 +19,7 @@ interval = "1h"
|
||||
language = "esql"
|
||||
license = "Elastic License v2"
|
||||
name = "Unusual File Creation by Web Server"
|
||||
risk_score = 47
|
||||
risk_score = 21
|
||||
rule_id = "894b7cc9-040b-427c-aca5-36b40d3667bf"
|
||||
setup = """## Setup
|
||||
|
||||
@@ -46,7 +46,7 @@ For more details on Elastic Agent configuration settings, refer to the [helper g
|
||||
- To complete the integration, select "Add Elastic Agent to your hosts" and continue to the next section to install the Elastic Agent on your hosts.
|
||||
For more details on Elastic Defend refer to the [helper guide](https://www.elastic.co/guide/en/security/current/install-endpoint.html).
|
||||
"""
|
||||
severity = "medium"
|
||||
severity = "low"
|
||||
tags = [
|
||||
"Domain: Endpoint",
|
||||
"OS: Linux",
|
||||
@@ -61,11 +61,31 @@ timestamp_override = "event.ingested"
|
||||
type = "esql"
|
||||
|
||||
query = '''
|
||||
from logs-endpoint.events.file-*
|
||||
from logs-endpoint.events.file-* metadata _id, _index, _version
|
||||
|
||||
// Ensure event.action values in a list are expanded
|
||||
| mv_expand event.action
|
||||
|
||||
| where
|
||||
host.os.type == "linux" and
|
||||
event.action == "creation" and (
|
||||
process.name in (
|
||||
"apache", "nginx", "apache2", "httpd", "lighttpd", "caddy", "mongrel_rails", "gunicorn",
|
||||
"uwsgi", "openresty", "cherokee", "h2o", "resin", "puma", "unicorn", "traefik", "tornado", "hypercorn",
|
||||
"daphne", "twistd", "yaws", "webfsd", "httpd.worker", "flask", "rails", "mongrel", "php-cgi",
|
||||
"php-fcgi", "php-cgi.cagefs", "catalina.sh", "hiawatha", "lswsctrl"
|
||||
) or
|
||||
process.name like "php-fpm*" or
|
||||
user.name in ("apache", "www-data", "httpd", "nginx", "lighttpd", "tomcat", "tomcat8", "tomcat9") or
|
||||
user.id in ("33", "498", "48")
|
||||
)
|
||||
|
||||
| keep
|
||||
@timestamp,
|
||||
_id,
|
||||
_index,
|
||||
_version,
|
||||
host.os.type,
|
||||
event.type,
|
||||
event.action,
|
||||
user.name,
|
||||
user.id,
|
||||
@@ -73,85 +93,70 @@ from logs-endpoint.events.file-*
|
||||
process.executable,
|
||||
file.path,
|
||||
agent.id,
|
||||
host.name
|
||||
| where
|
||||
@timestamp > now() - 1 hours and
|
||||
host.os.type == "linux" and
|
||||
event.type == "change" and
|
||||
event.action in ("rename", "creation") and (
|
||||
user.name in (
|
||||
"apache", "www-data", "httpd", "nginx", "lighttpd", "tomcat", "tomcat8", "tomcat9", "ftp", "ftpuser", "ftpd"
|
||||
) or
|
||||
user.id in ("99", "33", "498", "48")
|
||||
) and (
|
||||
process.name in (
|
||||
"apache", "nginx", "apache2", "httpd", "lighttpd", "caddy", "node", "mongrel_rails", "java", "gunicorn",
|
||||
"uwsgi", "openresty", "cherokee", "h2o", "resin", "puma", "unicorn", "traefik", "tornado", "hypercorn",
|
||||
"daphne", "twistd", "yaws", "webfsd", "httpd.worker", "flask", "rails", "mongrel"
|
||||
) or
|
||||
process.name like "php-*" or
|
||||
process.name like "python*" or
|
||||
process.name like "ruby*" or
|
||||
process.name like "perl*"
|
||||
)
|
||||
host.name,
|
||||
event.dataset,
|
||||
data_stream.namespace
|
||||
|
||||
| stats
|
||||
Esql.event_count = count(),
|
||||
Esql.agent_id_count_distinct = count_distinct(agent.id),
|
||||
Esql.host_name_values = values(host.name),
|
||||
Esql.agent_id_values = values(agent.id)
|
||||
Esql.agent_id_values = values(agent.id),
|
||||
Esql.event_dataset_values = values(event.dataset),
|
||||
Esql.data_stream_namespace_values = values(data_stream.namespace)
|
||||
|
||||
by process.executable, file.path
|
||||
|
||||
| where
|
||||
Esql.agent_id_count_distinct == 1 and
|
||||
Esql.event_count < 5
|
||||
| sort Esql.event_count asc
|
||||
| limit 100
|
||||
'''
|
||||
|
||||
|
||||
[[rule.threat]]
|
||||
framework = "MITRE ATT&CK"
|
||||
|
||||
[[rule.threat.technique]]
|
||||
id = "T1505"
|
||||
name = "Server Software Component"
|
||||
reference = "https://attack.mitre.org/techniques/T1505/"
|
||||
|
||||
[[rule.threat.technique.subtechnique]]
|
||||
id = "T1505.003"
|
||||
name = "Web Shell"
|
||||
reference = "https://attack.mitre.org/techniques/T1505/003/"
|
||||
|
||||
|
||||
|
||||
[rule.threat.tactic]
|
||||
id = "TA0003"
|
||||
name = "Persistence"
|
||||
reference = "https://attack.mitre.org/tactics/TA0003/"
|
||||
|
||||
[[rule.threat]]
|
||||
framework = "MITRE ATT&CK"
|
||||
|
||||
[[rule.threat.technique]]
|
||||
id = "T1059"
|
||||
name = "Command and Scripting Interpreter"
|
||||
reference = "https://attack.mitre.org/techniques/T1059/"
|
||||
|
||||
[[rule.threat.technique.subtechnique]]
|
||||
id = "T1059.004"
|
||||
name = "Unix Shell"
|
||||
reference = "https://attack.mitre.org/techniques/T1059/004/"
|
||||
|
||||
|
||||
|
||||
[rule.threat.tactic]
|
||||
id = "TA0002"
|
||||
name = "Execution"
|
||||
reference = "https://attack.mitre.org/tactics/TA0002/"
|
||||
|
||||
[[rule.threat]]
|
||||
framework = "MITRE ATT&CK"
|
||||
|
||||
[[rule.threat.technique]]
|
||||
id = "T1071"
|
||||
name = "Application Layer Protocol"
|
||||
reference = "https://attack.mitre.org/techniques/T1071/"
|
||||
|
||||
|
||||
[rule.threat.tactic]
|
||||
id = "TA0011"
|
||||
name = "Command and Control"
|
||||
reference = "https://attack.mitre.org/tactics/TA0011/"
|
||||
|
||||
|
||||
Reference in New Issue
Block a user