From 79f433efe57cae5086695631c1212dc1e6aca2cd Mon Sep 17 00:00:00 2001 From: Johan Bjerke Date: Thu, 15 Jun 2023 10:30:33 +0200 Subject: [PATCH] Move term filter to first command for better performance --- detections/endpoint/detect_baron_samedit_cve_2021_3156.yml | 2 +- .../endpoint/detect_baron_samedit_cve_2021_3156_segfault.yml | 4 ++-- 2 files changed, 3 insertions(+), 3 deletions(-) diff --git a/detections/endpoint/detect_baron_samedit_cve_2021_3156.yml b/detections/endpoint/detect_baron_samedit_cve_2021_3156.yml index ae6e87e0a8..0f1db83218 100644 --- a/detections/endpoint/detect_baron_samedit_cve_2021_3156.yml +++ b/detections/endpoint/detect_baron_samedit_cve_2021_3156.yml @@ -7,7 +7,7 @@ status: experimental type: TTP description: This search detects the heap-based buffer overflow of sudoedit data_source: [] -search: '`linux_hosts` | search "sudoedit -s \\" | `detect_baron_samedit_cve_2021_3156_filter`' +search: '`linux_hosts` "sudoedit -s \\" | `detect_baron_samedit_cve_2021_3156_filter`' how_to_implement: Splunk Universal Forwarder running on Linux systems, capturing logs from the /var/log directory. The vulnerability is exposed when a non privledged user tries passing in a single \ character at the end of the command while using diff --git a/detections/endpoint/detect_baron_samedit_cve_2021_3156_segfault.yml b/detections/endpoint/detect_baron_samedit_cve_2021_3156_segfault.yml index 4b2008ecca..70f59666a5 100644 --- a/detections/endpoint/detect_baron_samedit_cve_2021_3156_segfault.yml +++ b/detections/endpoint/detect_baron_samedit_cve_2021_3156_segfault.yml @@ -7,8 +7,8 @@ status: experimental type: TTP description: This search detects the heap-based buffer overflow of sudoedit data_source: [] -search: '`linux_hosts` | search sudoedit segfault | stats count min(_time) as firstTime - max(_time) as lastTime by host | search count > 5 | `detect_baron_samedit_cve_2021_3156_segfault_filter`' +search: '`linux_hosts` TERM(sudoedit) TERM(segfault) | stats count min(_time) as firstTime + max(_time) as lastTime by host | where count > 5 | `detect_baron_samedit_cve_2021_3156_segfault_filter`' how_to_implement: Splunk Universal Forwarder running on Linux systems (tested on Centos and Ubuntu), where segfaults are being logged. This also captures instances where the exploit has been compiled into a binary. The detection looks for greater than