Added detection testing service results inLinux Setuid Using Chmod Utility

This commit is contained in:
root
2022-01-04 11:36:47 +00:00
parent ff3172c7c0
commit 4c40ac8961
@@ -15,18 +15,19 @@ description: This analytic looks for suspicious chmod utility execution to enabl
is the SGID, or set group id bit. It is similar to the SUID bit, except it can temporarily
change group membership, usually to execute a program. The SGID bit is set if an
s or an S appears in the group section of permissions.
search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes
WHERE (Processes.process_name = chmod OR Processes.process = "*chmod *") AND Processes.process IN("* g+s *", "* u+s *", "* 4777 *", "* 4577 *")
by Processes.dest Processes.user Processes.parent_process_name Processes.process_name Processes.process Processes.process_id Processes.parent_process_id Processes.process_guid
| `drop_dm_object_name(Processes)`
| `security_content_ctime(firstTime)`
| `security_content_ctime(lastTime)`
| `linux_setuid_using_chmod_utility_filter`'
search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time)
as lastTime from datamodel=Endpoint.Processes WHERE (Processes.process_name = chmod
OR Processes.process = "*chmod *") AND Processes.process IN("* g+s *", "* u+s *",
"* 4777 *", "* 4577 *") by Processes.dest Processes.user Processes.parent_process_name
Processes.process_name Processes.process Processes.process_id Processes.parent_process_id
Processes.process_guid | `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)`
| `security_content_ctime(lastTime)` | `linux_setuid_using_chmod_utility_filter`'
how_to_implement: To successfully implement this search, you need to be ingesting
logs with the process name, parent process, and command-line executions from your
endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the
Sysmon TA.
known_false_positives: administrator or network operator can execute this command. filter is needed
Sysmon TA.
known_false_positives: administrator or network operator can execute this command.
filter is needed
references:
- https://www.hackingarticles.in/linux-privilege-escalation-using-capabilities/
tags:
@@ -46,17 +47,16 @@ tags:
- Splunk Cloud
required_fields:
- _time
- Processes.dest
- Processes.user
- Processes.parent_process_name
- Processes.process_name
- Processes.process
- Processes.process_id
- Processes.dest
- Processes.user
- Processes.parent_process_name
- Processes.process_name
- Processes.process
- Processes.process_id
- Processes.parent_process_id
security_domain: endpoint
impact: 70
confidence: 70
# (impact * confidence)/100
confidence: 70
risk_score: 49
context:
- source:endpoint
@@ -73,3 +73,4 @@ tags:
- CIS 3
- CIS 5
- CIS 16
automated_detection_testing: passed