mirror of
https://github.com/elastic/protections-artifacts
synced 2026-06-08 14:02:19 +00:00
Updating artifacts
This commit is contained in:
+97
@@ -0,0 +1,97 @@
|
||||
[rule]
|
||||
description = """
|
||||
This rule detects DNS requests initiated by suspicious process executables. Malware authors may use these requests to
|
||||
communicate with command and control infrastructure, exfiltrate data from the target system, or to download payloads for
|
||||
later execution.
|
||||
"""
|
||||
id = "503823dd-722f-4f23-84fc-8a6024f505f2"
|
||||
license = "Elastic License v2"
|
||||
name = "DNS Request by Suspicious Process Executable"
|
||||
os_list = ["linux"]
|
||||
version = "1.0.4"
|
||||
|
||||
query = '''
|
||||
sequence by process.entity_id with maxspan=10s
|
||||
[process where event.type == "start" and event.action == "exec" and (
|
||||
process.executable like (
|
||||
"./*", "/var/tmp/*", "/dev/shm/*", "/run/*", "/var/run/*", "/boot/*", "/sys/*",
|
||||
"/lost+found/*", "/var/mail/*"
|
||||
) or
|
||||
process.name like ".*"
|
||||
) and
|
||||
not (
|
||||
process.executable like (
|
||||
"./usr/bin/podman", "./", "/dev/.buildkit_qemu_emulator", "/u01/*/webtier/ohs/bin/.apachectl",
|
||||
"/usr/local/share/npm-global/lib/node_modules/opencode-ai/bin/.opencode",
|
||||
"./usr/bin/qemu-aarch64-static"
|
||||
) or
|
||||
process.parent.executable in ("/usr/bin/skopeo", "/usr/bin/buildah") or
|
||||
process.args == "datadog-ipc-helper"
|
||||
)]
|
||||
[dns where event.action == "lookup_result" and dns.question.name != "localhost" and
|
||||
not (
|
||||
dns.question.name == "pypi.org" or
|
||||
(process.executable like "/home/*/.elastic-ramen" and dns.question.name in ("registry.npmjs.org", "models.dev"))
|
||||
)
|
||||
]
|
||||
'''
|
||||
|
||||
min_endpoint_version = "9.3.0"
|
||||
optional_actions = []
|
||||
[[actions]]
|
||||
action = "kill_process"
|
||||
field = "process.entity_id"
|
||||
state = 0
|
||||
|
||||
[[actions]]
|
||||
action = "kill_process"
|
||||
field = "process.entity_id"
|
||||
state = 1
|
||||
|
||||
[[actions]]
|
||||
action = "kill_process"
|
||||
field = "process.parent.entity_id"
|
||||
state = 0
|
||||
|
||||
[[actions]]
|
||||
action = "kill_process"
|
||||
field = "process.parent.entity_id"
|
||||
state = 1
|
||||
|
||||
[[threat]]
|
||||
framework = "MITRE ATT&CK"
|
||||
[[threat.technique]]
|
||||
id = "T1204"
|
||||
name = "User Execution"
|
||||
reference = "https://attack.mitre.org/techniques/T1204/"
|
||||
[[threat.technique.subtechnique]]
|
||||
id = "T1204.002"
|
||||
name = "Malicious File"
|
||||
reference = "https://attack.mitre.org/techniques/T1204/002/"
|
||||
|
||||
|
||||
|
||||
[threat.tactic]
|
||||
id = "TA0002"
|
||||
name = "Execution"
|
||||
reference = "https://attack.mitre.org/tactics/TA0002/"
|
||||
[[threat]]
|
||||
framework = "MITRE ATT&CK"
|
||||
[[threat.technique]]
|
||||
id = "T1071"
|
||||
name = "Application Layer Protocol"
|
||||
reference = "https://attack.mitre.org/techniques/T1071/"
|
||||
[[threat.technique.subtechnique]]
|
||||
id = "T1071.004"
|
||||
name = "DNS"
|
||||
reference = "https://attack.mitre.org/techniques/T1071/004/"
|
||||
|
||||
|
||||
|
||||
[threat.tactic]
|
||||
id = "TA0011"
|
||||
name = "Command and Control"
|
||||
reference = "https://attack.mitre.org/tactics/TA0011/"
|
||||
|
||||
[internal]
|
||||
min_endpoint_version = "9.3.0"
|
||||
+11
-9
@@ -9,7 +9,7 @@ license = "Elastic License v2"
|
||||
name = "DNS Request to Dynamic DNS via Suspicious Executable"
|
||||
os_list = ["linux"]
|
||||
reference = ["https://www.rapid7.com/blog/post/tr-new-whitepaper-stealthy-bpfdoor-variants/"]
|
||||
version = "1.0.3"
|
||||
version = "1.0.4"
|
||||
|
||||
query = '''
|
||||
sequence by process.entity_id with maxspan=10s
|
||||
@@ -20,18 +20,20 @@ sequence by process.entity_id with maxspan=10s
|
||||
"./*", "/tmp/*", "/var/tmp/*", "/dev/shm/*", "/run/*", "/var/run/*", "/boot/*", "/sys/*",
|
||||
"/lost+found/*", "/proc/*", "/var/mail/*", "/var/www/*", "/home/*/*", "/root/*"
|
||||
)
|
||||
) and not (
|
||||
) and
|
||||
not (
|
||||
(
|
||||
process.parent.name in ("bash", "node") and
|
||||
(
|
||||
process.parent.name in ("bash", "node") and
|
||||
(
|
||||
process.working_directory in ("/usr/local/meshcentral", "/opt/meshcentral/meshcentral", "/usr/local/mesh_services/meshagent") or
|
||||
process.parent.args in ("/usr/local/meshcentral/node_modules/meshcentral", "/home/periodic/dyndns-noip.sh")
|
||||
)
|
||||
) or
|
||||
process.working_directory in ("/usr/local/meshcentral", "/opt/meshcentral/meshcentral", "/usr/local/mesh_services/meshagent") or
|
||||
process.parent.args in ("/usr/local/meshcentral/node_modules/meshcentral", "/home/periodic/dyndns-noip.sh")
|
||||
)
|
||||
) or
|
||||
(
|
||||
process.command_line == "python3 -m app.run_scheduled_update" and
|
||||
process.parent.args == "./workflow_unified.sh"
|
||||
)
|
||||
) or
|
||||
process.executable == "/usr/bin/qbittorrent-nox"
|
||||
)]
|
||||
[dns where event.action == "lookup_result" and dns.question.name like~ (
|
||||
"*.no-ip.com", "*.no-ip.org", "*.no-ip.biz", "*.no-ip.info", "*.noip.com", "*.afraid.org", "*.changeip.com",
|
||||
|
||||
+23
-5
@@ -7,16 +7,19 @@ id = "c14705f7-ebd3-4cf7-88b3-6bff2d832f1b"
|
||||
license = "Elastic License v2"
|
||||
name = "Hidden Executable Initiated Egress Network Connection"
|
||||
os_list = ["linux"]
|
||||
version = "1.0.6"
|
||||
version = "1.0.7"
|
||||
|
||||
query = '''
|
||||
sequence by process.entity_id with maxspan=10s
|
||||
[process where event.type == "start" and event.action == "exec" and process.name like ".*" and
|
||||
process.command_line regex ".*[0-9]{1,3}\\.[0-9]{1,3}\\.[0-9]{1,3}\\.[0-9]{1,3}.*" and
|
||||
not process.executable like (
|
||||
"/home/*/.npm/_npx/*/node_modules/opencode-ai/bin/.opencode",
|
||||
"/home/*/.local/share/fnm/node-versions/*/installation/lib/node_modules/opencode-ai/bin/.opencode"
|
||||
)]
|
||||
not (
|
||||
process.executable like (
|
||||
"/home/*/.npm/_npx/*/node_modules/opencode-ai/bin/.opencode",
|
||||
"/home/*/.local/share/fnm/node-versions/*/installation/lib/node_modules/opencode-ai/bin/.opencode"
|
||||
) or
|
||||
process.parent.executable == "/usr/bin/buildah"
|
||||
)]
|
||||
[network where event.type == "start" and event.action == "connection_attempted" and not (
|
||||
destination.ip == null or destination.ip == "0.0.0.0" or cidrmatch(
|
||||
destination.ip, "10.0.0.0/8", "127.0.0.0/8", "169.254.0.0/16", "172.16.0.0/12", "192.0.0.0/24", "192.0.0.0/29",
|
||||
@@ -31,11 +34,26 @@ sequence by process.entity_id with maxspan=10s
|
||||
|
||||
min_endpoint_version = "7.15.0"
|
||||
optional_actions = []
|
||||
[[actions]]
|
||||
action = "kill_process"
|
||||
field = "process.entity_id"
|
||||
state = 0
|
||||
|
||||
[[actions]]
|
||||
action = "kill_process"
|
||||
field = "process.entity_id"
|
||||
state = 1
|
||||
|
||||
[[actions]]
|
||||
action = "kill_process"
|
||||
field = "process.parent.entity_id"
|
||||
state = 0
|
||||
|
||||
[[actions]]
|
||||
action = "kill_process"
|
||||
field = "process.parent.entity_id"
|
||||
state = 1
|
||||
|
||||
[[threat]]
|
||||
framework = "MITRE ATT&CK"
|
||||
[[threat.technique]]
|
||||
|
||||
+7
-3
@@ -19,7 +19,7 @@ reference = [
|
||||
"https://book.hacktricks.xyz/generic-methodologies-and-resources/tunneling-and-port-forwarding",
|
||||
"https://github.com/erebe/wstunnel",
|
||||
]
|
||||
version = "1.0.3"
|
||||
version = "1.0.4"
|
||||
|
||||
query = '''
|
||||
process where event.type == "start" and event.action == "exec" and (
|
||||
@@ -103,8 +103,12 @@ not (
|
||||
process.args like "ssh*"
|
||||
) or
|
||||
process.parent.args == "/usr/bin/crun" or
|
||||
process.executable in ("/usr/bin/podman", "/usr/bin/crontab", "/usr/bin/rg", "/usr/bin/ssh", "/usr/bin/autossh") or
|
||||
process.parent.command_line == "runc init"
|
||||
process.executable in (
|
||||
"/usr/bin/podman", "/usr/bin/crontab", "/usr/bin/rg", "/usr/bin/ssh", "/usr/bin/autossh", "/usr/local/bin/rtk", "/usr/lib/autossh/autossh"
|
||||
) or
|
||||
process.executable like "/tmp/.mount_cursor*/ripgrep/bin/rg" or
|
||||
process.parent.command_line == "runc init" or
|
||||
process.args == "/usr/bin/autossh"
|
||||
)
|
||||
'''
|
||||
|
||||
|
||||
+2
-2
@@ -7,7 +7,7 @@ id = "49ab63a4-ed52-49ac-855b-c298b38b0cb9"
|
||||
license = "Elastic License v2"
|
||||
name = "Egress Network Connection from Deleted Executable by Root"
|
||||
os_list = ["linux"]
|
||||
version = "1.0.16"
|
||||
version = "1.0.17"
|
||||
|
||||
query = '''
|
||||
network where event.type == "start" and event.action == "connection_attempted" and process.executable like "* (deleted)" and
|
||||
@@ -25,7 +25,7 @@ not (
|
||||
"/var/lib/waagent/*", "/usr/local/bin/*", "/sbin/*", "/usr/sbin/*", "/usr/local/sbin/*", "/usr/local/lib/*",
|
||||
"/usr/lib64/*", "/var/tmp/go-build*", "/app/extra/slack*", "/projects/hash-manager/dist/*/hash-manager*",
|
||||
"/nextcloud/custom_apps/notify_push/bin/x86_64/notify_push*", "/usr/local/lad/bin/mdsd*",
|
||||
"/run/containerd/io.containerd.runtime.v2.task/k8s.io/*/longhorn*",
|
||||
"/run/containerd/io.containerd.runtime.v2.task/k8s.io/*/longhorn*", "/tmp/*/bin/kilo*",
|
||||
"/root/.antigravity-server/bin/*/extensions/antigravity/bin/language_server_linux_x64*"
|
||||
) or
|
||||
process.name in ("dockerd", "teleport", "zed-editor", "datacollector", "exe")
|
||||
|
||||
+3
-3
@@ -7,17 +7,17 @@ it via command and control.
|
||||
"""
|
||||
id = "fbc224a0-5469-4c0c-953d-fc57e0293197"
|
||||
license = "Elastic License v2"
|
||||
name = "Execution of In-Memory File via Interactive Session"
|
||||
name = "Execution of Memory File Descriptor via Interactive Session"
|
||||
os_list = ["linux"]
|
||||
reference = [
|
||||
"https://github.com/MythicAgents/merlin/blob/main/Payload_Type/merlin/container/commands/memfd.go",
|
||||
"https://x-c3ll.github.io/posts/fileless-memfd_create/",
|
||||
]
|
||||
version = "1.0.20"
|
||||
version = "1.0.21"
|
||||
|
||||
query = '''
|
||||
process where event.type == "start" and event.action == "exec" and process.parent.executable != null and
|
||||
process.executable like "/proc/*/fd/*" and process.interactive == true and
|
||||
process.executable regex """/proc/(self|[0-9]{1,7})/fd/[0-9]{1,7}""" and process.interactive == true and
|
||||
not (
|
||||
process.command_line in ("runc init", "/var/gdn/assets/linux/bin/runc init", "/usr/sbin/pfman", "lxc-attach -n rdsd.lv") or
|
||||
process.args == "datadog-ipc-helper" or
|
||||
+2
-2
@@ -6,10 +6,10 @@ child process execution is uncommon and may indicate an attempt to evade securit
|
||||
"""
|
||||
id = "edc713a8-f352-4b12-ba50-b24944dfbd2d"
|
||||
license = "Elastic License v2"
|
||||
name = "In-Memory Child Process Execution"
|
||||
name = "Memory File Descriptor Child Process Execution"
|
||||
os_list = ["linux"]
|
||||
reference = ["https://man7.org/linux/man-pages/man2/memfd_create.2.html"]
|
||||
version = "1.0.4"
|
||||
version = "1.0.5"
|
||||
|
||||
query = '''
|
||||
process where event.type == "start" and event.action == "exec" and process.parent.executable like "?memfd:*" and
|
||||
+2
-2
@@ -6,10 +6,10 @@ execution is uncommon and may indicate an attempt to evade security controls.
|
||||
"""
|
||||
id = "de860e9f-be00-4045-ba04-ba8a5008d3b4"
|
||||
license = "Elastic License v2"
|
||||
name = "In-Memory Process Execution"
|
||||
name = "Memory File Descriptor Process Execution"
|
||||
os_list = ["linux"]
|
||||
reference = ["https://man7.org/linux/man-pages/man2/memfd_create.2.html"]
|
||||
version = "1.0.1"
|
||||
version = "1.0.2"
|
||||
|
||||
query = '''
|
||||
process where event.type == "start" and event.action == "exec" and process.executable like "?memfd:*"
|
||||
+23
-21
@@ -6,35 +6,37 @@ and then execute it after which is establishes outbound network connections (C2)
|
||||
"""
|
||||
id = "4c8b9c6f-4d85-4fa9-9104-16f7a99aded6"
|
||||
license = "Elastic License v2"
|
||||
name = "Network Activity from In-Memory File"
|
||||
name = "Network Activity from Memory File Descriptor"
|
||||
os_list = ["linux"]
|
||||
reference = [
|
||||
"https://github.com/MythicAgents/merlin/blob/main/Payload_Type/merlin/container/commands/memfd.go",
|
||||
"https://x-c3ll.github.io/posts/fileless-memfd_create/",
|
||||
]
|
||||
version = "1.0.16"
|
||||
version = "1.0.17"
|
||||
|
||||
query = '''
|
||||
sequence by process.entity_id with maxspan=10s
|
||||
[process where event.type == "start" and event.action == "exec" and process.executable like "/proc/*/fd/*" and
|
||||
not (
|
||||
process.args like ("/usr/lib/systemd/systemd-executor", "/nix/store/*/systemd-executor*") or
|
||||
process.parent.executable like (
|
||||
"/usr/sbin/runc", "/usr/bin/dockerd", "/lib/systemd/systemd", "/usr/lib/systemd/systemd", "/nix/store/*/systemd",
|
||||
"/opt/sentinelone/bin/addon-host", "/opt/gitlab/embedded/bin/gitlab-kas", "/usr/sbin/nordlayerd", "/sbin/init",
|
||||
"/proc/self/fd/*/*"
|
||||
) or
|
||||
process.command_line == "runc init"
|
||||
)]
|
||||
[network where event.type == "start" and event.action == "connection_attempted" and not (
|
||||
cidrmatch(destination.ip, "127.0.0.0/8", "169.254.0.0/16", "172.16.0.0/12", "192.0.0.0/24",
|
||||
"192.0.0.0/29", "192.0.0.8/32", "192.0.0.9/32", "192.0.0.10/32", "192.0.0.170/32", "192.0.0.171/32",
|
||||
"192.0.2.0/24", "192.31.196.0/24", "192.52.193.0/24", "192.168.0.0/16", "192.88.99.0/24", "224.0.0.0/4",
|
||||
"100.64.0.0/10", "192.175.48.0/24","198.18.0.0/15", "198.51.100.0/24", "203.0.113.0/24", "240.0.0.0/4", "::1",
|
||||
"FE80::/10", "FF00::/8"
|
||||
) or
|
||||
process.name == "check-new-release-gtk"
|
||||
)]
|
||||
[process where event.type == "start" and event.action == "exec" and
|
||||
process.executable regex """/proc/(self|[0-9]{1,7})/fd/[0-9]{1,7}""" and
|
||||
not (
|
||||
process.args like ("/usr/lib/systemd/systemd-executor", "/nix/store/*/systemd-executor*") or
|
||||
process.parent.executable like (
|
||||
"/usr/sbin/runc", "/usr/bin/dockerd", "/lib/systemd/systemd", "/usr/lib/systemd/systemd", "/nix/store/*/systemd",
|
||||
"/opt/sentinelone/bin/addon-host", "/opt/gitlab/embedded/bin/gitlab-kas", "/usr/sbin/nordlayerd", "/sbin/init",
|
||||
"/proc/self/fd/*/*"
|
||||
) or
|
||||
process.command_line == "runc init"
|
||||
)]
|
||||
[network where event.type == "start" and event.action == "connection_attempted" and
|
||||
not (
|
||||
cidrmatch(destination.ip, "127.0.0.0/8", "169.254.0.0/16", "172.16.0.0/12", "192.0.0.0/24",
|
||||
"192.0.0.0/29", "192.0.0.8/32", "192.0.0.9/32", "192.0.0.10/32", "192.0.0.170/32", "192.0.0.171/32",
|
||||
"192.0.2.0/24", "192.31.196.0/24", "192.52.193.0/24", "192.168.0.0/16", "192.88.99.0/24", "224.0.0.0/4",
|
||||
"100.64.0.0/10", "192.175.48.0/24","198.18.0.0/15", "198.51.100.0/24", "203.0.113.0/24", "240.0.0.0/4", "::1",
|
||||
"FE80::/10", "FF00::/8"
|
||||
) or
|
||||
process.name == "check-new-release-gtk"
|
||||
)]
|
||||
'''
|
||||
|
||||
min_endpoint_version = "8.3.0"
|
||||
@@ -7,7 +7,7 @@ id = "4daceba6-54be-4dfc-95ab-a4a9c19c77af"
|
||||
license = "Elastic License v2"
|
||||
name = "System Binary Copied or Moved"
|
||||
os_list = ["linux"]
|
||||
version = "1.0.15"
|
||||
version = "1.0.16"
|
||||
|
||||
query = '''
|
||||
process where event.type == "start" and event.action == "exec" and process.name in ("cp", "mv") and
|
||||
@@ -65,18 +65,20 @@ process.args in (
|
||||
process.args like ("/var/tmp/dracut.*/initramfs/*", "/var/tmp/mkinitramfs_*", "/opt/jail/driver-jail/*") or
|
||||
process.parent.args like (
|
||||
"/var/tmp/rpm-tmp*", "/usr/sbin/rear", "/usr/lib/usrmerge/convert-usrmerge", "/usr/share/initramfs-tools/hooks/zz-busybox",
|
||||
"./libtool", "/var/lib/dpkg/info/dash.postinst", "*./libtool*", "/usr/bin/mkinitcpio"
|
||||
"./libtool", "/var/lib/dpkg/info/dash.postinst", "*./libtool*", "/usr/bin/mkinitcpio", "/sbin/rear"
|
||||
) or
|
||||
process.command_line in (
|
||||
"mv kubectl /usr/bin/kubectl", "mv ./kubectl /usr/bin/kubectl", "cp kubectl /usr/local/bin/kubectl",
|
||||
"mv kubectl /usr/local/bin/kubectl", "mv ./kubectl /usr/local/bin/kubectl"
|
||||
"mv kubectl /usr/local/bin/kubectl", "mv ./kubectl /usr/local/bin/kubectl",
|
||||
"/usr/bin/coreutils --coreutils-prog-shebang=cp /usr/bin/cp /usr/bin/sh /tmp"
|
||||
) or
|
||||
(process.parent.command_line like "/nix/store/*" and process.command_line == "mv /bin/.sh.tmp /bin/sh") or
|
||||
(process.parent.name == "shtool" and process.command_line == "mv /usr/local/bin/#INST@*# /usr/local/bin/php") or
|
||||
(
|
||||
process.args like "./curl.leap*.x86_64" and
|
||||
process.working_directory like "/opt/SIGOS/sitedata/exec/*"
|
||||
)
|
||||
) or
|
||||
process.parent.command_line == "/usr/bin/runc init"
|
||||
)
|
||||
'''
|
||||
|
||||
|
||||
+5
-3
@@ -8,7 +8,7 @@ id = "aa02591f-c9e6-4317-841e-0b075b9515ff"
|
||||
license = "Elastic License v2"
|
||||
name = "Linux Suspicious Child Process Execution via Interactive Shell"
|
||||
os_list = ["linux"]
|
||||
version = "1.0.22"
|
||||
version = "1.0.23"
|
||||
|
||||
query = '''
|
||||
process where event.type == "start" and event.action == "exec" and process.args in ("-i", "-il", "-li") and process.args_count <= 2 and
|
||||
@@ -23,13 +23,15 @@ process.parent.name like (
|
||||
"/usr/scratch/xar/23e8559c/bin/python"
|
||||
) or
|
||||
process.parent.command_line in (
|
||||
"/bin/sh -c bash -i </dev/tty >/dev/tty 2>/dev/tty", "/bin/bash --login --posix", "bash -c sudo su - oracle; $SHELL -i"
|
||||
"/bin/sh -c bash -i </dev/tty >/dev/tty 2>/dev/tty", "/bin/bash --login --posix", "bash -c sudo su - oracle; $SHELL -i",
|
||||
"/bin/bash /opt/scripts/health-check.sh"
|
||||
) or
|
||||
process.parent.command_line like (
|
||||
"/usr/scratch/*poetry shell", "*/u01/app/oracle.ahf/tfa/internal/tmp/*.sh*", "*/opt/oracle/oracle.ahf/tfa/internal/*.sh*",
|
||||
"bash -c ls -al; $SHELL -i", "bash -c cd ~/GIT/salt/pillars; $SHELL -i", "bash -c cd ~/GIT/ansible-infra; $SHELL -i",
|
||||
"bash -c cd ~/GIT/salt/states; $SHELL -i", "bash -c cd ~/GIT/puppet/hieradata; $SHELL -i",
|
||||
"bash -c cd ~/GIT/puppet/ind_legacy; $SHELL -i"
|
||||
"bash -c cd ~/GIT/puppet/ind_legacy; $SHELL -i",
|
||||
"""bash -c sudo -iu oracle bash -ic 'do_host P1 "hostname;/home/*/scripts/get_status;"'; $SHELL -i"""
|
||||
) or
|
||||
process.command_line == "/opt/cursor.appimage -i" or
|
||||
process.parent.executable like (
|
||||
|
||||
@@ -12,7 +12,7 @@ reference = [
|
||||
"https://pberba.github.io/security/2022/01/30/linux-threat-hunting-for-persistence-systemd-timers-cron/",
|
||||
"https://www.elastic.co/security-labs/primer-on-persistence-mechanisms",
|
||||
]
|
||||
version = "1.0.20"
|
||||
version = "1.0.21"
|
||||
|
||||
query = '''
|
||||
process where event.type == "start" and event.action == "exec" and process.parent.name in ("systemd", "cron", "crond") and
|
||||
@@ -30,7 +30,8 @@ not (
|
||||
"sh -c ldd /var/tmp/dracut*/initramfs/usr/bin/mkfifo*",
|
||||
"""/bin/sh -c curl*http://127.0.0.1:*""",
|
||||
"/bin/sh -c curl -sSL https://*/scripts/linux/syslog-archival/report_syslog_v3.sh | bash -x > /var/log/report_syslog_v3.debug.out 2>&1",
|
||||
"*cpanel*.zendesk.com/api/v2/ticket_metrics.json*, *fortigate-backup.sh*hc-ping.com*", "/bin/sh -c /usr/bin/curl -s http://scripts.*.lan:8080/*"
|
||||
"*cpanel*.zendesk.com/api/v2/ticket_metrics.json*, *fortigate-backup.sh*hc-ping.com*", "/bin/sh -c /usr/bin/curl -s http://scripts.*.lan:8080/*",
|
||||
"*/ec/tr/docflow/logs/tc.session.expire*", "*get.upwind.io/sensor.sh*", "*/usr/contact/ela/bin/ela_lic_prot.py*"
|
||||
) or
|
||||
process.command_line in (
|
||||
"/bin/sh -c /usr/bin/flock -n /dev/shm/loadwatch.lock -c /usr/local/lp/bin/loadwatch &> /dev/null",
|
||||
|
||||
@@ -9,14 +9,16 @@ id = "c1556f07-4184-42dc-a55c-866011a63715"
|
||||
license = "Elastic License v2"
|
||||
name = "Setcap setuid/setgid Capability Set"
|
||||
os_list = ["linux"]
|
||||
version = "1.0.1"
|
||||
version = "1.0.2"
|
||||
|
||||
query = '''
|
||||
process where event.type == "start" and event.action == "exec" and
|
||||
process.name == "setcap" and process.command_line like "*cap_set?id+ep*" and
|
||||
not (
|
||||
process.parent.name in ("jem", "vzctl") or
|
||||
process.args like "/usr/bin/new?idmap"
|
||||
process.args like "/usr/bin/new?idmap" or
|
||||
process.parent.executable like "/var/lib/dpkg/info/*.postinst" or
|
||||
process.parent.args like "/var/lib/dpkg/info/*.postinst"
|
||||
)
|
||||
'''
|
||||
|
||||
|
||||
+7
-4
@@ -11,7 +11,7 @@ reference = [
|
||||
"https://pberba.github.io/security/2022/01/30/linux-threat-hunting-for-persistence-systemd-timers-cron/",
|
||||
"https://www.elastic.co/security-labs/primer-on-persistence-mechanisms",
|
||||
]
|
||||
version = "1.0.1"
|
||||
version = "1.0.2"
|
||||
|
||||
query = '''
|
||||
process where event.type == "start" and event.action == "exec" and process.parent.name == "systemd" and
|
||||
@@ -70,7 +70,7 @@ not (
|
||||
"/bin/sh -c curl -s https://*/retrieve-validca.sh | bash -s /data/certificate > /data/log/valica.log 2>&1 && supervisorctl apache2 reload >>/data/log/valica.log 2>&1",
|
||||
"bash -c chmod +x /opt/forticlientems/bin/ubuntu24_upgrade_check.sh && /opt/forticlientems/bin/ubuntu24_upgrade_check.sh", "/bin/sh -c /bin/chmod 777 /upload/cms-embossing/*",
|
||||
"""/bin/sh -c /usr/bin/timeout 60 /bin/sh -c 'while ! /usr/bin/timeout 1 /usr/bin/host www.*.com >/dev/null 2>&1; do /bin/sleep 0.1; done' && /bin/echo "DNS works!"""",
|
||||
"*.gr/index.php?option=com_acymailing&ctrl=cron*"
|
||||
"*.gr/index.php?option=com_acymailing&ctrl=cron*", "*_sync_last_success_timestamp_seconds*10.10.20.204:9091/metrics*"
|
||||
) or
|
||||
process.command_line in (
|
||||
"/bin/sh -c /usr/bin/flock -n /dev/shm/loadwatch.lock -c /usr/local/lp/bin/loadwatch &> /dev/null",
|
||||
@@ -78,14 +78,17 @@ not (
|
||||
"/bin/bash -c curl -fs https://get.upwind.io/sensor.sh | bash -s -- upgrade",
|
||||
"/bin/bash -c curl -s https://get.upwind.io/sensor.sh | bash -s -- upgrade",
|
||||
"/bin/sh -c /opt/arcsight/backup_local/backup.sh || /opt/arcsight/backup_local/backup_error.sh",
|
||||
"""/usr/bin/sh -c echo date=$(date +"%Y%m%d") > /dev/shm/mag/sptwweb.env"""
|
||||
"""/usr/bin/sh -c echo date=$(date +"%Y%m%d") > /dev/shm/mag/sptwweb.env""",
|
||||
"/bin/bash -c curl -fsSLO https://get.upwind.io/sensor.sh && echo \"$(curl -fsSL https://get.upwind.io/sensor.sh.sha256) sensor.sh\" | sha256sum -c - && bash sensor.sh upgrade",
|
||||
"/bin/bash -lc timeout 45 /usr/bin/claude --model claude-haiku-4-5 -p \"reply: pong\" > /tmp/claude-quota-refresh.last 2>&1 || true",
|
||||
"/bin/sh -c echo \"$(date) $(whoami)\" >>/tmp/log"
|
||||
) or
|
||||
process.args like (
|
||||
"[ ! -e *", "ansible *", "php -q /var/www/*php > /tmp/datastore*", "wget --proxy=off*cat*batch_trigger.log",
|
||||
"sudo curl*raw.githubusercontent.com/*/backup-scripts/refs/heads/main/fortigate-backup.sh*",
|
||||
"/usr/bin/curl -s -H*zendesk.com/api/v2/ticket_metrics.json*", "export PM2_HOME=*",
|
||||
"/usr/bin/curl*/var/log/checkdiskusage.log", "ps*/opt/fortinet/fortisiem/linux-agent/tmp/*",
|
||||
"iostat*/tmp/iostat.cache"
|
||||
"iostat*/tmp/iostat.cache", "/usr/local/psa/admin/sbin/modules/aast-dnssec/event*"
|
||||
) or
|
||||
process.working_directory like "/opt/nessus_agent/*"
|
||||
)
|
||||
|
||||
+56
@@ -0,0 +1,56 @@
|
||||
[rule]
|
||||
description = """
|
||||
Identifies an attempt to exploit a local privilege escalation via the unshare command. The unshare command allows a
|
||||
process to create a new namespace and set the capabilities of the process. This can be used to escalate privileges to
|
||||
root.
|
||||
"""
|
||||
id = "f483675e-1c8f-4ce4-80b3-34c646911385"
|
||||
license = "Elastic License v2"
|
||||
name = "Potential Local Privilege Escalation via Unshare"
|
||||
os_list = ["linux"]
|
||||
version = "1.0.1"
|
||||
|
||||
query = '''
|
||||
sequence by process.parent.entity_id with maxspan=60s
|
||||
[process where event.action == "exec" and event.type == "start" and
|
||||
process.name == "unshare" and process.args in ("-r", "-rm", "-m", "-U", "--user") and user.id != 0]
|
||||
[process where event.action == "uid_change" and event.type == "change" and user.id == 0 and process.parent.user.id != 0]
|
||||
'''
|
||||
|
||||
min_endpoint_version = "8.2.0"
|
||||
optional_actions = []
|
||||
[[actions]]
|
||||
action = "kill_process"
|
||||
field = "process.entity_id"
|
||||
state = 0
|
||||
|
||||
[[actions]]
|
||||
action = "kill_process"
|
||||
field = "process.entity_id"
|
||||
state = 1
|
||||
|
||||
[[actions]]
|
||||
action = "kill_process"
|
||||
field = "process.parent.entity_id"
|
||||
state = 0
|
||||
|
||||
[[actions]]
|
||||
action = "kill_process"
|
||||
field = "process.parent.entity_id"
|
||||
state = 1
|
||||
|
||||
[[threat]]
|
||||
framework = "MITRE ATT&CK"
|
||||
[[threat.technique]]
|
||||
id = "T1068"
|
||||
name = "Exploitation for Privilege Escalation"
|
||||
reference = "https://attack.mitre.org/techniques/T1068/"
|
||||
|
||||
|
||||
[threat.tactic]
|
||||
id = "TA0004"
|
||||
name = "Privilege Escalation"
|
||||
reference = "https://attack.mitre.org/tactics/TA0004/"
|
||||
|
||||
[internal]
|
||||
min_endpoint_version = "8.2.0"
|
||||
+3
-2
@@ -9,7 +9,7 @@ license = "Elastic License v2"
|
||||
name = "Shell Privileged Mode from Non-Standard Path with Root Effective User"
|
||||
os_list = ["linux"]
|
||||
reference = ["https://gtfobins.github.io/#+suid"]
|
||||
version = "1.0.1"
|
||||
version = "1.0.2"
|
||||
|
||||
query = '''
|
||||
process where event.action == "exec" and user.name == "root" and user.Ext.real.name != "root" and
|
||||
@@ -17,7 +17,8 @@ process where event.action == "exec" and user.name == "root" and user.Ext.real.n
|
||||
process.executable != null and process.parent.executable != null and
|
||||
process.executable like ("/var/tmp/*", "/tmp/*", "/dev/shm/*", "/run/*", "/var/run/*") and
|
||||
not (process.executable like "/tmp/newroot/usr/bin/*" and process.parent.executable like "/tmp/newroot/bin/*") and
|
||||
not (process.executable like "/run/k3s/containerd/*" and process.parent.executable like "/run/k3s/containerd/*")
|
||||
not (process.executable like "/run/k3s/containerd/*" and process.parent.executable like "/run/k3s/containerd/*") and
|
||||
not process.executable in ("/tmp/newroot/usr/sbin/sudo", "/tmp/newroot/usr/bin/sudo")
|
||||
'''
|
||||
|
||||
min_endpoint_version = "8.6.0"
|
||||
|
||||
@@ -11,13 +11,13 @@ license = "Elastic License v2"
|
||||
name = "Information Stealer Collection via Find"
|
||||
os_list = ["macos"]
|
||||
reference = ["https://socket.dev/blog/10-npm-typosquatted-packages-deploy-credential-harvester"]
|
||||
version = "1.0.3"
|
||||
version = "1.0.4"
|
||||
|
||||
query = '''
|
||||
sequence by process.entity_id with maxspan=10s
|
||||
[process where event.type == "start" and event.action == "exec" and process.name == "find" and
|
||||
process.args like "/Users/*/Library/Application Support/*" and process.args == "-type" and process.args == "f"]
|
||||
[file where file.extension == "txt"]
|
||||
[process where event.type == "start" and event.action == "exec" and process.name == "find" and
|
||||
process.args like "/Users/*/Library/Application Support/*" and process.args == "-type" and process.args == "f"]
|
||||
[file where file.extension == "txt" and Effective_process.executable != "/Library/Elastic/Endpoint/elastic-endpoint.app/Contents/MacOS/elastic-endpoint"]
|
||||
'''
|
||||
|
||||
min_endpoint_version = "8.16.0"
|
||||
|
||||
+9
-7
@@ -7,16 +7,18 @@ id = "a6994646-d314-4ee0-be1f-1d694dc969e7"
|
||||
license = "Elastic License v2"
|
||||
name = "Potential Data Collection in Temporary Directory by Hidden Executable"
|
||||
os_list = ["macos"]
|
||||
version = "1.0.7"
|
||||
version = "1.0.8"
|
||||
|
||||
query = '''
|
||||
sequence by process.entity_id, file.path with maxspan=30s
|
||||
[file where event.action == "modification" and process.name like~ ".*" and
|
||||
file.path like ("/private/tmp/*", "/tmp/*", "/var/tmp/*") and
|
||||
not process.executable like "/nix/store/*"]
|
||||
[file where event.action == "deletion" and process.name like~ ".*" and
|
||||
file.path like ("/private/tmp/*", "/tmp/*", "/var/tmp/*") and
|
||||
not process.executable like "/nix/store/*"]
|
||||
[file where event.action == "modification" and process.name like~ ".*" and
|
||||
file.path like ("/private/tmp/*", "/tmp/*", "/var/tmp/*") and
|
||||
not process.executable like "/nix/store/*" and
|
||||
not Effective_process.executable == "/Applications/Visual Studio Code - Insiders.app/Contents/MacOS/Code - Insiders"]
|
||||
[file where event.action == "deletion" and process.name like~ ".*" and
|
||||
file.path like ("/private/tmp/*", "/tmp/*", "/var/tmp/*") and
|
||||
not process.executable like "/nix/store/*" and
|
||||
not Effective_process.executable == "/Applications/Visual Studio Code - Insiders.app/Contents/MacOS/Code - Insiders"]
|
||||
'''
|
||||
|
||||
min_endpoint_version = "8.11.1"
|
||||
|
||||
@@ -11,7 +11,7 @@ reference = [
|
||||
"https://moonlock.com/atomic-macos-stealer",
|
||||
"https://medium.com/@dineshdevadoss04/breaking-down-atomic-macos-stealer-amos-8cd5eea56024",
|
||||
]
|
||||
version = "1.0.8"
|
||||
version = "1.0.9"
|
||||
|
||||
query = '''
|
||||
process where event.type == "start" and event.action == "exec" and process.name == "ditto" and
|
||||
@@ -20,7 +20,9 @@ process where event.type == "start" and event.action == "exec" and process.name
|
||||
process.args like~ "*.zip*" and
|
||||
(process.parent.code_signature.exists == false or process.parent.code_signature.trusted == false) and
|
||||
not process.parent.executable like ("/opt/homebrew/*", "/usr/local/Cellar/*", "/usr/local/Homebrew/*") and
|
||||
not process.Ext.effective_parent.executable like ("/Library/Intune/Microsoft Intune Agent.app/Contents/MacOS/IntuneMdmDaemon", "/opt/homebrew/*")
|
||||
not process.Ext.effective_parent.executable like ("/Library/Intune/Microsoft Intune Agent.app/Contents/MacOS/IntuneMdmDaemon",
|
||||
"/opt/homebrew/*",
|
||||
"/Applications/Ghostty.app/Contents/MacOS/ghostty")
|
||||
'''
|
||||
|
||||
min_endpoint_version = "8.11.1"
|
||||
|
||||
@@ -7,7 +7,7 @@ id = "0701ab8c-9abc-41e1-8af7-2d937778e73f"
|
||||
license = "Elastic License v2"
|
||||
name = "Suspicious Image Creation via ScreenCapture"
|
||||
os_list = ["macos"]
|
||||
version = "1.0.7"
|
||||
version = "1.0.8"
|
||||
|
||||
query = '''
|
||||
sequence by process.entity_id with maxspan=10s
|
||||
@@ -26,7 +26,10 @@ sequence by process.entity_id with maxspan=10s
|
||||
"/Users/*/Library/Application Support/Claude/claude-code/*/claude.app/*",
|
||||
"/Applications/Codex.app/*",
|
||||
"/private/var/folders/*/AppTranslocation/*/Visual Studio Code.app/*",
|
||||
"/Users/*/.local/bin/uv")]
|
||||
"/Users/*/.local/bin/uv",
|
||||
"/Applications/Warp.app/*",
|
||||
"/Applications/Obsidian.app/*",
|
||||
"/Applications/Tabby.app/*")]
|
||||
[file where event.action == "modification" and file.path like ("/Users/Shared/*", "/tmp/*", "/private/tmp/*")]
|
||||
'''
|
||||
|
||||
|
||||
+5
-2
@@ -8,11 +8,14 @@ id = "4154c8ce-c718-4641-80db-a6a52276f1a4"
|
||||
license = "Elastic License v2"
|
||||
name = "Potential Binary Masquerading via Invalid Code Signature"
|
||||
os_list = ["macos"]
|
||||
version = "1.0.39"
|
||||
version = "1.0.40"
|
||||
|
||||
query = '''
|
||||
process where event.action == "exec" and
|
||||
process.name like ("com.apple.*", "com.jamf.*", "jamf*", "zoom.us") and
|
||||
(
|
||||
process.name like ("com.apple.*", "com.jamf.*", "jamf*", "zoom.us") or
|
||||
process.executable like "/Users/*/Library/com.apple.*"
|
||||
) and
|
||||
(process.code_signature.trusted == false or process.code_signature.exists == false) and
|
||||
not (process.code_signature.subject_name in ("Software Signing", "com.apple.WebKit.Networking", "com.apple.WebKit.WebContent") and
|
||||
process.name in
|
||||
|
||||
@@ -15,7 +15,7 @@ reference = [
|
||||
"https://blog.xpnsec.com/macos-injection-via-third-party-frameworks/",
|
||||
"https://wojciechregula.blog/post/learn-xpc-exploitation-part-3-code-injections/",
|
||||
]
|
||||
version = "1.0.37"
|
||||
version = "1.0.38"
|
||||
|
||||
query = '''
|
||||
process where event.action == "process_open" and
|
||||
@@ -35,7 +35,8 @@ process where event.action == "process_open" and
|
||||
startswith~(process.executable, Target.process.executable)) and
|
||||
not process.hash.sha256 : ("d41e02b5366b186a237f33150baa7c5ef4747ba06646a193ab9ba5125fc6ef7a",
|
||||
"bee1a00ffb1c4b7c2c4784a1fdcb849dc7853b9deb5173ff4c5a08209c84bc26",
|
||||
"6ac6f81d80afff9b6ee9d3608d9964566a39188d0166ae867df97c624e632b98") and
|
||||
"6ac6f81d80afff9b6ee9d3608d9964566a39188d0166ae867df97c624e632b98",
|
||||
"8698f4e54c64667c4a4c7ccde3fbcd7babc6478a5e8e22732732f633cc2fc499") and
|
||||
not (process.executable like "/Users/*/micromamba/envs/grid/bin/python*" and Target.process.executable in ("/bin/bash", "/usr/bin/which", "/usr/bin/uname")) and
|
||||
not (process.executable like "/Users/*/.local/share/uv/python/cpython-*-macos-aarch64-none/bin/python*" and Target.process.executable like "/Users/*/Code/eis-ray/.venv/lib/python*/site-packages/ray/core/src/ray/gcs/gcs_server") and
|
||||
not (process.executable like "/Users/*/anaconda?/bin/python*" and Target.process.executable like "/Users/*/anaconda?/envs/python*/bin/python*")
|
||||
|
||||
+3
-2
@@ -11,7 +11,7 @@ os_list = ["macos"]
|
||||
reference = [
|
||||
"https://www.jamf.com/blog/cryptojacking-macos-malware-discovered-by-jamf-threat-labs/?utm_source=twitter&utm_medium=social&utm_campaign=blog-promo&utm_content=2023-02-23_shared_",
|
||||
]
|
||||
version = "1.0.36"
|
||||
version = "1.0.37"
|
||||
|
||||
query = '''
|
||||
file where event.action != "deletion" and
|
||||
@@ -28,7 +28,8 @@ file where event.action != "deletion" and
|
||||
"/Library/Developer/PrivateFrameworks/CoreSimulator.framework/Versions/A/XPCServices/SimulatorTrampoline.xpc/Contents/MacOS/SimulatorTrampoline",
|
||||
"/Library/Application Support/JAMF/Jamf.app/Contents/MacOS/JamfManagementService.app/Contents/MacOS/JamfManagementService",
|
||||
"/Library/Kandji/Kandji Agent.app/Contents/Helpers/Kandji Library Manager.app/Contents/MacOS/kandji-library-manager",
|
||||
"/opt/jc/bin/jumpcloud-agent")
|
||||
"/opt/jc/bin/jumpcloud-agent",
|
||||
"/Library/Iru/Iru Agent.app/Contents/Helpers/Iru Library Manager.app/Contents/MacOS/kandji-library-manager")
|
||||
'''
|
||||
|
||||
min_endpoint_version = "8.10.2"
|
||||
|
||||
@@ -1,69 +0,0 @@
|
||||
[rule]
|
||||
description = """
|
||||
Detects when Node spawns Python in order to execute a hidden Python script in the /Users directory on macOS. North
|
||||
Korean threat groups have been observed distributing malicious Nodejs applications that unpack a malicious Python script
|
||||
in the current users home directory and execute it in order to download and execute a follow on second stage payload.
|
||||
"""
|
||||
id = "235f605a-3d3e-4c00-bed9-58d068ccca13"
|
||||
license = "Elastic License v2"
|
||||
name = "Hidden Python Script Execution via Nodejs"
|
||||
os_list = ["macos"]
|
||||
reference = ["https://x.com/dimitribest/status/1782609281897902426"]
|
||||
version = "1.0.4"
|
||||
|
||||
query = '''
|
||||
process where event.type == "start" and event.action == "exec" and
|
||||
process.args like~ "python*" and process.args like~ ("/Users/*/.*", "/tmp/.*", "/private/tmp/.*") and
|
||||
process.args_count == 2 and process.name like~ "python*" and process.parent.name == "node" and
|
||||
not process.args like~ ("/Users/*/.vscode/*", "/Users/*/.claude/*")
|
||||
'''
|
||||
|
||||
min_endpoint_version = "8.10.2"
|
||||
optional_actions = []
|
||||
[[actions]]
|
||||
action = "kill_process"
|
||||
field = "process.entity_id"
|
||||
state = 0
|
||||
|
||||
[[actions]]
|
||||
action = "kill_process"
|
||||
field = "process.parent.entity_id"
|
||||
state = 0
|
||||
|
||||
[[threat]]
|
||||
framework = "MITRE ATT&CK"
|
||||
[[threat.technique]]
|
||||
id = "T1059"
|
||||
name = "Command and Scripting Interpreter"
|
||||
reference = "https://attack.mitre.org/techniques/T1059/"
|
||||
[[threat.technique.subtechnique]]
|
||||
id = "T1059.006"
|
||||
name = "Python"
|
||||
reference = "https://attack.mitre.org/techniques/T1059/006/"
|
||||
|
||||
[[threat.technique.subtechnique]]
|
||||
id = "T1059.007"
|
||||
name = "JavaScript"
|
||||
reference = "https://attack.mitre.org/techniques/T1059/007/"
|
||||
|
||||
|
||||
|
||||
[threat.tactic]
|
||||
id = "TA0002"
|
||||
name = "Execution"
|
||||
reference = "https://attack.mitre.org/tactics/TA0002/"
|
||||
[[threat]]
|
||||
framework = "MITRE ATT&CK"
|
||||
[[threat.technique]]
|
||||
id = "T1105"
|
||||
name = "Ingress Tool Transfer"
|
||||
reference = "https://attack.mitre.org/techniques/T1105/"
|
||||
|
||||
|
||||
[threat.tactic]
|
||||
id = "TA0011"
|
||||
name = "Command and Control"
|
||||
reference = "https://attack.mitre.org/tactics/TA0011/"
|
||||
|
||||
[internal]
|
||||
min_endpoint_version = "8.10.2"
|
||||
+4
-2
@@ -9,12 +9,14 @@ license = "Elastic License v2"
|
||||
name = "Suspicious Remote Javascript Evaluation via Nodejs"
|
||||
os_list = ["macos"]
|
||||
reference = ["https://kl4r10n.tech/blog/dprk-new-malware"]
|
||||
version = "1.0.4"
|
||||
version = "1.0.5"
|
||||
|
||||
query = '''
|
||||
sequence with maxspan=20s
|
||||
[network where event.action == "connection_attempted" and process.name == "node" and
|
||||
not destination.domain in ("registry.npmjs.org", "classic.yarnpkg.com")] by process.entity_id
|
||||
not destination.domain in ("registry.npmjs.org", "classic.yarnpkg.com", "platform.claude.com", "api.anthropic.com", "registry.yarnpkg.com", "api.z.ai",
|
||||
"telemetry.nuxt.com", "api.fontshare.com", "yarnpkg.com", "telemetry-staging.elastic.co", "elastic.litellm-prod.ai",
|
||||
"chatgpt.com", "bedrock-runtime.us-east-1.amazonaws.com")] by process.entity_id
|
||||
[process where event.type == "start" and event.action == "exec" and process.name == "node" and
|
||||
process.args == "-e" and process.args_count == 3 and
|
||||
not process.command_line : ("*try*require*postinstall*catch*", "*import*postinstall*catch*")] by process.parent.entity_id
|
||||
|
||||
+2
-1
@@ -8,7 +8,7 @@ license = "Elastic License v2"
|
||||
name = "Initial Access or Execution via Microsoft Office Application"
|
||||
os_list = ["macos"]
|
||||
reference = ["https://objective-see.com/blog/blog_0x4B.html"]
|
||||
version = "1.0.40"
|
||||
version = "1.0.41"
|
||||
|
||||
query = '''
|
||||
process where event.action == "exec" and
|
||||
@@ -74,6 +74,7 @@ process where event.action == "exec" and
|
||||
"/usr/sbin/networksetup"
|
||||
) and
|
||||
not (process.name == "sh" and process.command_line like~ "*$CFFIXED_USER_HOME/.zoteroIntegrationPipe*") and
|
||||
not (process.name in ("sh", "bash", "curl") and process.command_line like~ "*http://127.0.0.1:6969/binary*ppShuttle_*.bin*") and
|
||||
not process.Ext.effective_parent.executable like~ (
|
||||
"/Applications/ToDesk.app/Contents/MacOS/ToDesk_Service",
|
||||
"/Applications/Docker.app/Contents/MacOS/com.docker.backend",
|
||||
|
||||
+4
-2
@@ -7,7 +7,7 @@ id = "720e0265-03bc-4cb7-9116-7fad5ea9cdfc"
|
||||
license = "Elastic License v2"
|
||||
name = "Network Connect API from Unbacked Memory"
|
||||
os_list = ["windows"]
|
||||
version = "1.0.16"
|
||||
version = "1.0.17"
|
||||
|
||||
query = '''
|
||||
api where process.Ext.api.name == "connect" and process.Ext.api.summary: "*ipv4*" and
|
||||
@@ -87,7 +87,9 @@ api where process.Ext.api.name == "connect" and process.Ext.api.summary: "*ipv4*
|
||||
"f834e4447d0b4c421ac2a0a9b10304a47688f358a6db9c1281bffe44957bcc4e",
|
||||
"d0615bcbcaf0c64b2613c224924fce9e891a62287acc243a9b142ee0d021b207",
|
||||
"7c71327ab87990b1ac0446813f2f1e69c33cc634afab5857cfa9fca17d0cc37e",
|
||||
"ecbd9f72fe48043302f547643b26e2da9c12c4d8030d28e53f1651fb0e06a2ca") and
|
||||
"ecbd9f72fe48043302f547643b26e2da9c12c4d8030d28e53f1651fb0e06a2ca",
|
||||
"c11d8f8d419aee8d67166ae9eeed3999364fa41a7d701ede076f2d2ad8acb8be",
|
||||
"ad71a3681f0fa629133a67f04d64c626d995da07d04322238aa4997a2671735a") and
|
||||
|
||||
not _arraysearch(process.thread.Ext.call_stack, $entry, $entry.symbol_info : "Unbacked*" and
|
||||
$entry.callsite_trailing_bytes :
|
||||
|
||||
+4
-1
@@ -8,7 +8,7 @@ license = "Elastic License v2"
|
||||
name = "Sensitive File Access - Cloud Credentials"
|
||||
os_list = ["windows"]
|
||||
reference = ["https://github.com/GhostPack/Seatbelt"]
|
||||
version = "1.0.34"
|
||||
version = "1.0.35"
|
||||
|
||||
query = '''
|
||||
sequence by process.entity_id with maxspan=5m
|
||||
@@ -46,6 +46,9 @@ sequence by process.entity_id with maxspan=5m
|
||||
"?:\\users\\*\\AppData\\*\\gcloud\\access_tokens.db",
|
||||
"?:\\users\\*\\.azure\\accessTokens.json",
|
||||
"?:\\users\\*\\.azure\\azureProfile.json",
|
||||
"?:\\users\\*\\.azure\\msal_token_cache.json",
|
||||
"?:\\users\\*\\.azure\\msal_token_cache.bin",
|
||||
"?:\\users\\*\\.azure\\msal_http_cache.bin",
|
||||
"?:\\users\\*\\.aws\\credentials",
|
||||
"?:\\Users\\*\\.config\\git\\credentials")]
|
||||
'''
|
||||
|
||||
@@ -11,7 +11,7 @@ reference = [
|
||||
"https://aidenpearce369.github.io/offsec/AMSI-Memory-Bypass/",
|
||||
"https://modexp.wordpress.com/2019/06/03/disable-amsi-wldp-dotnet/",
|
||||
]
|
||||
version = "1.0.7"
|
||||
version = "1.0.8"
|
||||
|
||||
query = '''
|
||||
api where process.Ext.api.metadata.target_address_name like "amsi.dll*" and
|
||||
@@ -52,6 +52,7 @@ api where process.Ext.api.metadata.target_address_name like "amsi.dll*" and
|
||||
"c:\\windows\\assembly\\nativeimages_*.ni.dll",
|
||||
"c:\\windows\\winsxs\\temp\\pendingdeletes\\$$deleteme*",
|
||||
"c:\\windows\\system32\\mrt\\*\\mpengine.dll",
|
||||
"c:\\windows\\system32\\wbem\\fastprox.dll",
|
||||
"c:\\windows\\winsxs\\*.dll",
|
||||
"c:\\program files (x86)\\*",
|
||||
"c:\\program files\\*",
|
||||
|
||||
+2
-1
@@ -7,7 +7,7 @@ id = "002d9a6d-c09e-4d3f-a1c1-05b92dbdbb67"
|
||||
license = "Elastic License v2"
|
||||
name = "Cross Process API Activity with Truncated Stack"
|
||||
os_list = ["windows"]
|
||||
version = "1.0.4"
|
||||
version = "1.0.5"
|
||||
|
||||
query = '''
|
||||
api where process.Ext.api.behaviors == "cross-process" and process.Ext.api.behaviors == "truncated_stack" and
|
||||
@@ -24,6 +24,7 @@ api where process.Ext.api.behaviors == "cross-process" and process.Ext.api.behav
|
||||
"C:\\Program Files (x86)\\Adobe\\Acrobat *\\Acrobat\\AcroRd32.exe",
|
||||
"C:\\Program Files\\Git\\usr\\bin\\bash.exe",
|
||||
"C:\\Program Files\\Git\\usr\\bin\\sh.exe",
|
||||
"C:\\Program Files\\Git\\usr\\bin\\mintty.exe",
|
||||
"C:\\Program Files\\ESET\\ESET Security\\ekrn.exe",
|
||||
"C:\\Program Files (x86)\\Adobe\\Acrobat DC\\Acrobat\\Acrobat.exe",
|
||||
"C:\\Program Files (x86)\\Globus Connect Personal\\bin\\ext\\relaytool.exe") and
|
||||
|
||||
@@ -7,7 +7,7 @@ id = "27202cd8-c5a6-4b82-9bb8-f3da69a4d5d3"
|
||||
license = "Elastic License v2"
|
||||
name = "Native API Call from Unsigned Module"
|
||||
os_list = ["windows"]
|
||||
version = "1.0.10"
|
||||
version = "1.0.11"
|
||||
|
||||
query = '''
|
||||
api where
|
||||
@@ -98,16 +98,14 @@ $entry.subject_name in (
|
||||
)) and
|
||||
not _arraysearch(process.thread.Ext.call_stack, $entry,
|
||||
$entry.symbol_info like
|
||||
("c:\\windows\\sys?????\\ntdll.dll!LdrLoadDll*",
|
||||
"c:\\windows\\sys?????\\ntdll.dll!LdrResolveDelayLoadedAPI*",
|
||||
"c:\\windows\\sys?????\\ntdll.dll!LdrGetProcedureAddress*",
|
||||
"c:\\windows\\sys?????\\ntdll.dll!RtlAllocateHeap*",
|
||||
("c:\\windows\\*\\ntdll.dll!Ldr*",
|
||||
"c:\\windows\\*\\ntdll.dll!RtlAllocateHeap*",
|
||||
"c:\\windows\\sys?????\\ntdll.dll!RtlFreeHeap*",
|
||||
"c:\\windows\\sys?????\\ntdll.dll!RtlReAllocateHeap*",
|
||||
"c:\\windows\\sys?????\\ntdll.dll!RtlUnlockHeap*",
|
||||
"c:\\windows\\sys?????\\ntdll.dll!LdrInitializeThunk*",
|
||||
"c:\\windows\\sys?????\\ntdll.dll+0x*")) and
|
||||
not (process.executable : "\\\\?\\Volume{*}\\*.exe" and process.thread.Ext.call_stack_final_user_module.path like "?:\\*\\docker\\*\\windows\\*")
|
||||
not (process.executable : "\\\\?\\Volume{*}\\*.exe" and process.thread.Ext.call_stack_final_user_module.path like "?:\\*\\docker\\*\\windows\\*") and
|
||||
not process.thread.Ext.call_stack_summary like ("ntdll.dll|libpcre*.dll|libgobject-*.dll|ntdll.dll", "ntdll.dll|libffi-*.dll|libpython*.dll|ntdll.dll")
|
||||
'''
|
||||
|
||||
min_endpoint_version = "8.16.3"
|
||||
|
||||
@@ -0,0 +1,77 @@
|
||||
[rule]
|
||||
description = """
|
||||
Identifies attempts to change the memory page permissions of Event Tracing for Windows (ETW) functions in ntdll.dll to
|
||||
make them writable from an unsigned or suspicious module. This is a precursor to patching those functions via a raw
|
||||
pointer write, which can disable ETW-based telemetry and evade security tooling that relies on it.
|
||||
"""
|
||||
id = "a26e8618-136d-4988-a8a7-eb45d5f1d468"
|
||||
license = "Elastic License v2"
|
||||
name = "Potential ETW Bypass via VirtualProtect"
|
||||
os_list = ["windows"]
|
||||
reference = [
|
||||
"https://blog.xpnsec.com/hiding-your-dotnet-etw/",
|
||||
"https://www.elastic.co/security-labs/doubling-down-etw-callstacks",
|
||||
]
|
||||
version = "1.0.3"
|
||||
|
||||
query = '''
|
||||
api where process.Ext.api.name in ("VirtualProtect", "VirtualProtectEx") and
|
||||
process.Ext.api.metadata.target_address_name like ("ntdll.dll!Etw*", "ntdll.dll!NtTrace*") and
|
||||
process.Ext.api.parameters.protection like "?W*" and
|
||||
process.executable != null and
|
||||
process.thread.Ext.call_stack_final_user_module.hash.sha256 != null and
|
||||
not process.thread.Ext.call_stack_final_user_module.name in ("Unknown", "Undetermined") and
|
||||
not (process.executable : "?:\\Program Files\\Microsoft Visual Studio\\*\\IDE\\devenv.exe" and
|
||||
process.Ext.api.metadata.target_address_name like ("ntdll.dll!EtwUnregisterTraceGuid*", "ntdll.dll!EtwRegisterTraceGuids*")) and
|
||||
not _arraysearch(process.thread.Ext.call_stack, $entry, $entry.symbol_info like ("c:\\windows\\system32\\ntdll.dll!Ldr*", "c:\\program files\\microsoft sql server management studio*\\ide\\ssms.exe!SetOnAssertCallback*")) and
|
||||
not _arraysearch(process.thread.Ext.call_stack_final_user_module.code_signature, $entry, $entry.trusted == true and
|
||||
$entry.subject_name in ("Microsoft Windows Hardware Compatibility Publisher",
|
||||
"Microsoft Windows Software Compatibility Publisher",
|
||||
"Palo Alto Networks", "Sentinel Labs, Inc.",
|
||||
"Microsoft Corporation",
|
||||
"Check Point Software Technologies Ltd.",
|
||||
"ESET, spol. s r.o.",
|
||||
"Promon AS",
|
||||
"SAP",
|
||||
"NOVASYNC LABS PTE. LTD.",
|
||||
"Tonalio GmbH",
|
||||
"SentinelOne Inc.",
|
||||
"JetBrains s.r.o.",
|
||||
"Safetica a.s.",
|
||||
"ModuleWorks GmbH",
|
||||
"Star Finanz-Software Entwicklung und Vertriebs GmbH",
|
||||
"TRACKER SOFTWARE PRODUCTS (CANADA) LIMITED, TRACKER SOFTWARE PRODUCTS (CANADA) LIMITED")) and
|
||||
not (process.executable like "C:\\Program Files (x86)\\SFirmV*\\SFEbicsWorker.exe" and process.thread.Ext.call_stack_final_user_module.protection_provenance_path == "c:\\windows\\system32\\rundll32.exe") and
|
||||
not (process.parent.executable like "C:\\Program Files (x86)\\StarMoney*\\app\\StarMoney.exe" and process.thread.Ext.call_stack_final_user_module.protection_provenance_path == "c:\\windows\\system32\\rundll32.exe") and
|
||||
process.thread.Ext.call_stack_final_user_module.protection_provenance_path != "c:\\windows\\syswow64\\icu.dll" and
|
||||
not (process.thread.Ext.call_stack_final_user_module.path == "c:\\windows\\syswow64\\combase.dll" and process.Ext.api.summary == "VirtualProtect( ntdll.dll!EtwEventRegister, 0x5, RWX, R-X )")
|
||||
'''
|
||||
|
||||
min_endpoint_version = "8.16.3"
|
||||
optional_actions = []
|
||||
[[actions]]
|
||||
action = "kill_process"
|
||||
field = "process.entity_id"
|
||||
state = 0
|
||||
tree = true
|
||||
|
||||
[[threat]]
|
||||
framework = "MITRE ATT&CK"
|
||||
[[threat.technique]]
|
||||
id = "T1562"
|
||||
name = "Impair Defenses"
|
||||
reference = "https://attack.mitre.org/techniques/T1562/"
|
||||
[[threat.technique.subtechnique]]
|
||||
id = "T1562.001"
|
||||
name = "Disable or Modify Tools"
|
||||
reference = "https://attack.mitre.org/techniques/T1562/001/"
|
||||
|
||||
|
||||
|
||||
[threat.tactic]
|
||||
id = "TA0005"
|
||||
name = "Defense Evasion"
|
||||
reference = "https://attack.mitre.org/tactics/TA0005/"
|
||||
|
||||
[internal]
|
||||
min_endpoint_version = "8.16.3"
|
||||
+3
-2
@@ -7,7 +7,7 @@ id = "47167118-ba42-48e8-8555-dd50d98d21c4"
|
||||
license = "Elastic License v2"
|
||||
name = "Potential Suspended Process Code Injection"
|
||||
os_list = ["windows"]
|
||||
version = "1.0.15"
|
||||
version = "1.0.16"
|
||||
|
||||
query = '''
|
||||
api where process.Ext.api.name == "WriteProcessMemory" and
|
||||
@@ -17,7 +17,8 @@ api where process.Ext.api.name == "WriteProcessMemory" and
|
||||
Target.process.Ext.created_suspended == true and process.Ext.api.behaviors == "cross-process" and
|
||||
|
||||
/* WPM triggers multiple times at process creation */
|
||||
not _arraysearch(process.thread.Ext.call_stack, $entry, $entry.symbol_info like ("*\\kernelbase.dll!CreateProcess*", "*\\kernelbase.dll+0x*")) and
|
||||
not _arraysearch(process.thread.Ext.call_stack, $entry,
|
||||
$entry.symbol_info like ("*\\kernelbase.dll!CreateProcess*", "*\\kernelbase.dll+0x*", "c:\\windows\\*\\advapi32.dll!CreateProcessAsUser*")) and
|
||||
not (process.Ext.api.summary like ("*PEB*", "*PEB32*", "*ProcessStartupInfo*") and process.thread.Ext.call_stack_summary like "*Unknown*") and
|
||||
|
||||
/* unsigned or untrusted code signature */
|
||||
|
||||
+2
-2
@@ -7,7 +7,7 @@ id = "9c4bd6d6-9e2f-4ce2-8266-923e1799726c"
|
||||
license = "Elastic License v2"
|
||||
name = "Process Explorer Device Access by Unusual Process"
|
||||
os_list = ["windows"]
|
||||
version = "1.0.7"
|
||||
version = "1.0.8"
|
||||
|
||||
query = '''
|
||||
api where
|
||||
@@ -17,7 +17,7 @@ api where
|
||||
not (process.thread.Ext.call_stack_final_user_module.name : ("procexp64.exe", "procexp.exe", "handle64.exe", "handle.exe") and
|
||||
_arraysearch(process.thread.Ext.call_stack_final_user_module.code_signature, $caller, $caller.trusted == true and
|
||||
$caller.subject_name : "Microsoft Corporation")) and
|
||||
not (process.name : ("procexp64.exe", "procexp.exe", "Handle64.exe", "Handle.exe") and process.code_signature.subject_name : "Microsoft Corporation" and
|
||||
not (process.name : ("procexp64.exe", "procexp.exe", "Handle64.exe", "Handle.exe", "procexp64a.exe") and process.code_signature.subject_name : "Microsoft Corporation" and
|
||||
process.thread.Ext.call_stack_final_user_module.name in ("Unknown", "Undetermined") and process.code_signature.trusted == true) and
|
||||
not (process.thread.Ext.call_stack_final_user_module.name : ("procexp64.exe", "procexp.exe", "handle64.exe") and
|
||||
process.code_signature.subject_name : "Microsoft Corporation" and process.code_signature.trusted == true) and
|
||||
|
||||
+3
-1
@@ -7,7 +7,7 @@ id = "5c6c166c-a894-4263-918a-c7632014a486"
|
||||
license = "Elastic License v2"
|
||||
name = "Remote Memory Write to Trusted Target Process"
|
||||
os_list = ["windows"]
|
||||
version = "1.0.13"
|
||||
version = "1.0.14"
|
||||
|
||||
query = '''
|
||||
api where process.Ext.api.name == "WriteProcessMemory" and
|
||||
@@ -24,6 +24,8 @@ api where process.Ext.api.name == "WriteProcessMemory" and
|
||||
not (_arraysearch(process.thread.Ext.call_stack, $entry, $entry.symbol_info like ("*\\kernelbase.dll!CreateProcess*", "*\\kernelbase.dll+0x*"))
|
||||
and process.Ext.api.summary like ("*PEB*", "*PEB32*", "*ProcessStartupInfo*")) and
|
||||
|
||||
not _arraysearch(process.thread.Ext.call_stack, $entry, $entry.symbol_info like "c:\\windows\\system32\\ntdll.dll!Ldr*") and
|
||||
|
||||
not (process.Ext.api.summary like ("*PEB*", "*PEB32*", "*ProcessStartupInfo*") and
|
||||
process.thread.Ext.call_stack_summary like "ntdll.dll|*Unknown*") and
|
||||
|
||||
|
||||
+7
-7
@@ -7,7 +7,7 @@ id = "43e9d254-28e9-463d-9bc3-5e51721d4b8a"
|
||||
license = "Elastic License v2"
|
||||
name = "Suspicious API call via a Windows Installer Module"
|
||||
os_list = ["windows"]
|
||||
version = "1.0.10"
|
||||
version = "1.0.11"
|
||||
|
||||
query = '''
|
||||
api where process.name : "msiexec.exe" and
|
||||
@@ -19,12 +19,11 @@ api where process.name : "msiexec.exe" and
|
||||
/* noisy patterns - VP and WPM due to Image Load and Process Creation */
|
||||
not (process.Ext.api.metadata.target_address_name in ("ProcessStartupInfo", "PEB", "PEB32", "Data") and process.Ext.api.parameters.size <= 4544) and
|
||||
not _arraysearch(process.thread.Ext.call_stack, $entry,
|
||||
$entry.symbol_info like ("c:\\windows\\sys?????\\ntdll.dll!LdrLoadDll*",
|
||||
"c:\\windows\\sys?????\\kernelbase.dll!LoadLibrary*",
|
||||
"c:\\windows\\sys?????\\ntdll.dll!LdrUnloadDll*",
|
||||
"c:\\windows\\sys?????\\ntdll.dll!LdrResolveDelayLoadedAPI*",
|
||||
"c:\\windows\\system32\\ntdll.dll!LdrGetProcedureAddress*",
|
||||
"?:\\windows\\sys?????\\kernelbase.dll!CreateProcess*")) and
|
||||
$entry.symbol_info like ("c:\\windows\\*\\ntdll.dll!Ldr*",
|
||||
"c:\\windows\\*\\kernelbase.dll!LoadLibrary*",
|
||||
"?:\\windows\\*\\kernelbase.dll!CreateProcess*",
|
||||
"c:\\windows\\system32\\ntdll.dll!wcsnlen+*",
|
||||
"c:\\windows\\system32\\kernelbase.dll!GetProductInfo*")) and
|
||||
not _arraysearch(process.thread.Ext.call_stack, $entry,
|
||||
$entry.callsite_trailing_bytes in ("5a8bf850528b338b432003c28b08894b208b431c03c28b08894b1c03f28b4b0c03ca8d431c505756ffd15a580343088bf8528bf08b46fc83c0042bf08956088b")) and
|
||||
not (process.Ext.api.metadata.target_address_path like "c:\\windows\\syswow64\\*.dll" and process.Ext.api.parameters.size <= 4096) and
|
||||
@@ -35,6 +34,7 @@ api where process.name : "msiexec.exe" and
|
||||
("85da69c82e3d1faff1e60e6853e30230fc5e3b64faf4245e20089fe75912d910",
|
||||
"09e957a1d31b9cf8666add20613bf60b6a2d294586f8887961cc6a0e24680fb8",
|
||||
"3c60786fddc7fb00b2dab7bd2b6c33340e07c73ea8e3d6c47754bb9d15d83166",
|
||||
"e10c6189c60b9bc3b0e2603930b55eda886e0de4520b0c8ba7f060fbf3b30549",
|
||||
/* Kaspersky */
|
||||
"0c9891da5c64a519c11e7603a41e93e0ff3057cca238ee59ffb5b4a82985011a",
|
||||
"80f84a7b8aad0bdceba677e6a501f71b6b57878e34b6b557e1892083a32b7bd5",
|
||||
|
||||
+3
-2
@@ -7,7 +7,7 @@ id = "dfe28e03-9b0b-47f5-9753-65ed2666663f"
|
||||
license = "Elastic License v2"
|
||||
name = "External IP Address Discovery via Untrusted Program"
|
||||
os_list = ["windows"]
|
||||
version = "1.0.43"
|
||||
version = "1.0.44"
|
||||
|
||||
query = '''
|
||||
sequence by process.entity_id with maxspan=1m
|
||||
@@ -48,7 +48,8 @@ sequence by process.entity_id with maxspan=1m
|
||||
"821bd11693bf4b4b2b9f3c196036e1f4902abd95fb26873ea6c43e123b8c9431",
|
||||
"0b7161d83ea48142a8593ad721a1546440fcbe09fb83cf644fecd456e3a0c38e",
|
||||
"ef1941d82bb658e614b9857493bb2e0eedf14f619d28404294628d136573b3cd",
|
||||
"96ada02d961dcfacb396a911c495073887d8bd2a0dda4b491294c573e76af750")]
|
||||
"96ada02d961dcfacb396a911c495073887d8bd2a0dda4b491294c573e76af750",
|
||||
"f60c5057286d6f5ca454be1f59f519e6480111868b52a70af1c3ff1b6e736f4b")]
|
||||
[dns where
|
||||
dns.question.name :
|
||||
(
|
||||
|
||||
@@ -4,7 +4,7 @@ id = "6ad0c702-ddf0-4631-ac43-37eeea444ee6"
|
||||
license = "Elastic License v2"
|
||||
name = "Suspicious API Call from a PowerShell Script"
|
||||
os_list = ["windows"]
|
||||
version = "1.0.22"
|
||||
version = "1.0.23"
|
||||
|
||||
query = '''
|
||||
api where
|
||||
@@ -105,9 +105,8 @@ not _arraysearch(process.thread.Ext.call_stack, $entry,
|
||||
"8bf0488b4c2428488bf9488bcf488bf985f67479*")) and
|
||||
not (process.Ext.api.name in ("VirtualProtect", "VirtualAlloc") and
|
||||
_arraysearch(process.thread.Ext.call_stack, $entry,
|
||||
$entry.symbol_info like ("c:\\windows\\sys?????\\ntdll.dll!LdrLoadDll*",
|
||||
"c:\\windows\\sys?????\\ntdll.dll!LdrGetDllHandle*",
|
||||
"c:\\windows\\system32\\ntdll.dll!LdrResolveDelayLoadedAPI*",
|
||||
$entry.symbol_info like ("c:\\windows\\sy*\\ntdll.dll!Ldr*",
|
||||
"c:\\windows\\sy*\\kernelbase.dll!PackageSidFromProductId",
|
||||
"c:\\windows\\sys?????\\ntdll.dll!RtlAllocateHeap*",
|
||||
"c:\\windows\\sys?????\\dbgeng.dll!DebugCreateEx*",
|
||||
"c:\\windows\\system32\\ntdll.dll!LdrGetProcedureAddress*",
|
||||
|
||||
+3
-1
@@ -9,7 +9,7 @@ license = "Elastic License v2"
|
||||
name = "Suspicious String Value Written to Registry Run Key"
|
||||
os_list = ["windows"]
|
||||
reference = ["https://docs.microsoft.com/en-us/windows/win32/setupapi/run-and-runonce-registry-keys"]
|
||||
version = "1.0.41"
|
||||
version = "1.0.42"
|
||||
|
||||
query = '''
|
||||
registry where registry.data.strings != null and process.executable != null and
|
||||
@@ -90,6 +90,8 @@ registry where registry.data.strings != null and process.executable != null and
|
||||
"*:\\Users\\*\\Pictures\\*",
|
||||
"*:\\Users\\*\\Music\\*",
|
||||
"*:\\Users\\*\\Pictures\\*",
|
||||
"?:\\Users\\*\\Downloads\\*",
|
||||
"?:\\Users\\*\\Desktop\\*",
|
||||
"*\\AppData\\Roaming\\Microsoft\\Windows\\Start Menu\\Programs\\Startup\\*",
|
||||
"\\\\*.exe",
|
||||
"*javaw.exe* -jar *") and not
|
||||
|
||||
Reference in New Issue
Block a user