Branch was auto-updated.

This commit is contained in:
pyth0n1c
2022-01-24 10:51:01 -08:00
committed by GitHub
12 changed files with 371 additions and 0 deletions
@@ -0,0 +1,55 @@
name: Detect AutoSUID post exploitation tool
id: 0edd5862-56c9-11ec-b990-acde48001122
version: 1
date: '2021-12-06'
author: Rod Soto
type: TTP
datamodel:
- Endpoint
description: This search, detects Linux post exploitation tool AutoSUID, which is
an a tool that searches for SUID executables files in order to escalate privileges.
search: ' `sysmon_linux` CommandLine="find / -xdev -user root ( -perm -4000 -o -perm
-2000 -o -perm -6000 )" | stats count by Computer process process_current_directory
process_path | `detect_autosuid_post_exploitation_tool_filter`'
how_to_implement: This detection search is based on Splunk add-on for Microsoft Sysmon-Linux.
Need to install this add-on to parse fields correctly and execute detection search.
known_false_positives: Unless an administrator is using these commands to troubleshoot
or audit a system, the execution of these commands should be monitored.
references:
- https://attack.mitre.org/matrices/enterprise/linux/
- https://github.com/IvanGlinkin/AutoSUID
tags:
analytic_story:
- Linux Post-Exploitation
confidence: 90
context:
- Source: Endpoint
- Stage: Discovery
dataset:
- https://github.com/splunk/attack_data/raw/master/datasets/suspicious_behaviour/linux_post_exploitation/autoSUID.txt
impact: 90
kill_chain_phases:
- Exploitation
- Privilege Escalation
message: AutoSUID post exploitation tool detected
mitre_attack_id:
- T1069
- T1222
observable:
- name: Computer
type: Endpoint
role:
- Victim
product:
- Splunk Enterprise
- Splunk Enterprise Security
- Splunk Cloud
required_fields:
- _time
- Computer
- process
- process_path
- process_current_directory
risk_score: 81
security_domain: endpoint
automated_detection_testing: passed
@@ -0,0 +1,63 @@
name: Detect LinEnum execution
id: 570e5278-5479-11ec-89c8-acde48001122
version: 1
date: '2021-12-03'
author: Rod Soto
type: TTP
datamodel:
- Endpoint
description: LinEnum is a bash script that performs discovery commands for accounts,
processes, kernel version, applications, services, and uses the information from
these commands to present operator with ways of escalating privileges or further
exploitation of targeted host.
search: ' `sysmon_linux` CommandLine="grep -w aria2c\\|arp\\|ash\\|awk\\|base64\\|bash\\|busybox\\|cat\\|chmod\\|chown\\|cp\\|csh\\|curl\\|cut\\|dash\\|date\\|dd\\|diff\\|dmsetup\\|docker\\|ed\\|emacs\\|env\\|expand\\|expect\\|file\\|find\\|flock\\|fmt\\|fold\\|ftp\\|gawk\\|gdb\\|gimp\\|git\\|grep\\|head\\|ht\\|iftop\\|ionice\\|ip$\\|irb\\|jjs\\|jq\\|jrunscript\\|ksh\\|ld.so\\|ldconfig\\|less\\|logsave\\|lua\\|make\\|man\\|mawk\\|more\\|mv\\|mysql\\|nano\\|nawk\\|nc\\|netcat\\|nice\\|nl\\|nmap\\|node\\|od\\|openssl\\|perl\\|pg\\|php\\|pic\\|pico\\|python\\|readelf\\|rlwrap\\|rpm\\|rpmquery\\|rsync\\|ruby\\|run-parts\\|rvim\\|scp\\|script\\|sed\\|setarch\\|sftp\\|sh\\|shuf\\|socat\\|sort\\|sqlite3\\|ssh$\\|start-stop-daemon\\|stdbuf\\|strace\\|systemctl\\|tail\\|tar\\|taskset\\|tclsh\\|tee\\|telnet\\|tftp\\|time\\|timeout\\|ul\\|unexpand\\|uniq\\|unshare\\|vi\\|vim\\|watch\\|wget\\|wish\\|xargs\\|xxd\\|zip\\|zsh"
| stats count by Computer CommandLine user process_exec process_current_directory
| `detect_linenum_execution_filter` '
how_to_implement: This detection search is based on Splunk add-on for Microsoft Sysmon-Linux.
Need to install this add-on to parse fields correctly and execute detection search.
known_false_positives: Very rare to perform such an extensive grep on a system, however
certain monitoring tools can produce similar results. It is important if monitoring
tools are in place to verify what is the actual process directory of execution.
references:
- https://github.com/rebootuser/LinEnum
- https://book.hacktricks.xyz/linux-unix/linux-privilege-escalation-checklist
tags:
analytic_story:
- Linux Post-Exploitation
confidence: 90
context:
- Source: endpoint
- Stage: discovery
dataset:
- https://github.com/splunk/attack_data/raw/master/datasets/suspicious_behaviour/linux_post_exploitation/LinuxEnumd.txt
impact: 50
kill_chain_phases:
- Privilege Escalation
message: LinEnum post exploitation tool detected
mitre_attack_id:
- T1087
- T1069
- T1083
- T1057
- T1518
- T1082
- T1016
- T1033
observable:
- name: Computer
type: Endpoint
role:
- Victim
product:
- Splunk Enterprise
- Splunk Enterprise Security
- Splunk Cloud
required_fields:
- _time
- CommandLine
- user
- process_exec
- process_current_directory
risk_score: 45
security_domain: endpoint
automated_detection_testing: passed
@@ -0,0 +1,58 @@
name: Detect LinPeas Execution
id: 4ea6fa10-547c-11ec-a4f9-acde48001122
version: 1
date: '2021-12-03'
author: Rod Soto
type: TTP
datamodel:
- Endpoint
description: Linux local Privilege Escalation Awesome Script (linPEAS) is a script that searches for possible paths to escalate privileges.
search: ' `sysmon_linux` CommandLine!=null parent_process_exec=sudo OR parent_process_exec=bash OR CommandLine="cve-list" | stats count by Computer CommandLine user parent_process_exec process_path
| `detect_linpeas_execution_filter`'
how_to_implement: This detection search is based on Splunk add-on for Microsoft Sysmon-Linux. Need to install this add-on to parse fields correctly and execute detection search.
known_false_positives: This search may produce false positives as it will display many sudo executed processess however, the cve-list within the command line it is a clear indicator, operator is searching for local vulnerabilites.
references:
- https://book.hacktricks.xyz/linux-unix/linux-privilege-escalation-checklist
- https://github.com/carlospolop/PEASS-ng/tree/master/linPEAS
- https://attack.mitre.org/matrices/enterprise/linux/
tags:
analytic_story:
- Linux Post-Exploitation
confidence: 100
context:
- Source: endpoint
- Stage: discovery
dataset:
- https://github.com/splunk/attack_data/raw/master/datasets/suspicious_behaviour/linux_post_exploitation/linpeasdataset.txt
impact: 90
kill_chain_phases:
- Exploitation
- Privilege Escalation
message: LinPEAS post exploitation tool detected
mitre_attack_id:
- T1082
- T1083
- T1033
- T1087
- T1046
- T1057
- T1518
- T1033
observable:
- name: Computer
type: Endpoint
role:
- Victim
product:
- Splunk Enterprise
- Splunk Enterprise Security
- Splunk Cloud
required_fields:
- _time
- Computer
- CommandLine
- user
- parent_process_exec
- process_path
risk_score: 90
security_domain: endpoint
@@ -0,0 +1,57 @@
name: Detect Linux Exploit Suggester Execution
id: a4f34d5c-547b-11ec-ba88-acde48001122
version: 1
date: '2021-12-03'
author: Rod Soto
type: TTP
datamodel:
- Endpoint
description: This search detects Linux Exploit Suggester tool execution. This is a
tool that searches for vulnerabilities based on Kernel and Distribution versions
then queries public exploit databases.
search: ' `sysmon_linux` CommandLine="cvelist-file:" OR CommandLine="uname -a" OR
CommandLine="*exploit*" OR CommandLine="*exploit-db*" | stats count by CommandLine,user,Computer,action,signature,
process_name | `detect_linux_exploit_suggester_execution_filter`'
how_to_implement: This detection search is based on Splunk add-on for Microsoft Sysmon-Linux.
Need to install this add-on to parse fields correctly and execute detection search.
known_false_positives: Monitoring tools may produce similar commands although the
presence of "exploit-db" is very unusual.
references:
- https://book.hacktricks.xyz/linux-unix/linux-privilege-escalation-checklist
- https://attack.mitre.org/matrices/enterprise/linux/
tags:
analytic_story:
- Linux Post-Exploitation
confidence: 100
context:
- Source: endpoint
- Stage: discovery
dataset:
- https://github.com/splunk/attack_data/raw/master/datasets/suspicious_behaviour/linux_post_exploitation/linuxexploitsuggesterdatasets.txt
impact: 90
message: Linux Exploit Suggester post exploitation tool detected.
kill_chain_phases:
- Exploitation
- Privilege Escalation
mitre_attack_id:
- T1087
- T1083
- T1069
- T1057
- T1518
- T1082
observable:
- name: Computer
type: Endpoint
role:
- Victim
product:
- Splunk Enterprise
- Splunk Enterprise Security
- Splunk Cloud
required_fields:
- _time
- CommandLine
risk_score: 90
security_domain: endpoint
automated_detection_testing: passed
@@ -0,0 +1,54 @@
name: Detect MimiPenguin
id: 1ad20afa-547b-11ec-b4e7-acde48001122
version: 1
date: '2021-12-03'
author: Rod Soto
type: TTP
datamodel:
- Endpoint
description: MimiPenguin is a tool that dumps login passwords from current linux destop
users. This search detects execution of this tool.
search: ' `sysmon_linux` CommandLine="strings -e /etc/apache2/apache2.conf" OR CommandLine="strings
-e /etc/ssh/sshd_config" OR CommandLine="strings -e /etc/shadow" | stats count
by Computer parent_process process_current_directory user CommandLine | `detect_mimipenguin_filter`'
how_to_implement: This detection search is based on Splunk add-on for Microsoft Sysmon-Linux.
Need to install this add-on to parse fields correctly and execute detection search.
known_false_positives: Some of these commands may be executed by sysadmin however
not in the proximity and frequency, specially if querying for tools are that knonwn
not to be installed at target system.
references:
- https://github.com/huntergregal/mimipenguin
- https://attack.mitre.org/matrices/enterprise/linux/
tags:
analytic_story:
- Linux Post-Exploitation
confidence: 70
context:
- Source: endpoint
- Stage: discovery
dataset:
- https://github.com/splunk/attack_data/raw/master/datasets/suspicious_behaviour/linux_post_exploitation/mimipenguin.txt
impact: 50
kill_chain_phases:
- Privilege Escalation
message: MimiPenguin post exploitation tool detected
mitre_attack_id:
- T1552
observable:
- name: Computer
type: Endpoint
role:
- Victim
product:
- Splunk Enterprise
- Splunk Enterprise Security
- Splunk Cloud
required_fields:
- _time
- user
- Computer
- parent_process
- process_current_directory
risk_score: 35
security_domain: endpoint
automated_detection_testing: passed
+4
View File
@@ -0,0 +1,4 @@
definition: source=Syslog:Linux-Sysmon/Operational
description: customer specific splunk configurations(eg- index, source, sourcetype).
Replace the macro definition with configurations for your Splunk Environmnent.
name: sysmon_linux
+20
View File
@@ -0,0 +1,20 @@
name: Linux Post-Exploitation
id: d310ccfe-5477-11ec-ad05-acde48001122
version: 1
date: '2021-12-03'
author: Rod Soto
description: This analytic story detects popular Linux post exploitation tools such as autoSUID, LinEnum, LinPEAS, Linux Exploit Suggesters, MimiPenguin
narrative: These tools allow operators find possible exploits or paths for privilege escalation based on SUID binaries, user permissions, kernel version and distro version.
references:
- https://attack.mitre.org/matrices/enterprise/linux/
tags:
analytic_story:
- Linux Post-Exploitation
category:
- Adversary Tactics
- Privilege Escalation
product:
- Splunk Enterprise
- Splunk Enterprise Security
- Splunk Cloud
usecase: Security Monitoring
@@ -0,0 +1,12 @@
name: Detect AutoSUID post exploitation tool Unit Test
tests:
- name: Detect AutoSUID post exploitation tool
file: endpoint/detect_autosuid_post_exploitation_tool.yml
pass_condition: '| stats count | where count > 0'
earliest_time: '-24h'
latest_time: 'now'
attack_data:
- file_name: autoSUID.txt
data: https://github.com/splunk/attack_data/raw/master/datasets/suspicious_behaviour/linux_post_exploitation/autoSUID.txt
source: "Syslog:Linux-Sysmon/Operational"
sourcetype: "sysmon_linux"
@@ -0,0 +1,12 @@
name: Detect LinEnum execution unit Test
tests:
- name: Detect LinEnum execution
file: endpoint/detect_linenum_execution.yml
pass_condition: '| stats count | where count > 0'
earliest_time: '-24h'
latest_time: 'now'
attack_data:
- file_name: LinuxEnumd.txt
data: https://github.com/splunk/attack_data/raw/master/datasets/suspicious_behaviour/linux_post_exploitation/LinuxEnumd.txt
source: "Syslog:Linux-Sysmon/Operational"
sourcetype: "sysmon_linux"
@@ -0,0 +1,12 @@
name: Detect LinPeas Execution Unit Test
tests:
- name: Detect LinPeas Execution
file: endpoint/detect_linpeas_execution.yml
pass_condition: '| stats count | where count > 0'
earliest_time: '-24h'
latest_time: 'now'
attack_data:
- file_name: linpeasdataset.txt
data: https://github.com/splunk/attack_data/raw/master/datasets/suspicious_behaviour/linux_post_exploitation/linpeasdataset.txt
source: "Syslog:Linux-Sysmon/Operational"
sourcetype: "sysmon_linux"
@@ -0,0 +1,12 @@
name: Detect Linux Exploit Suggester Execution Unit Test
tests:
- name: Detect Linux Exploit Suggester Execution
file: endpoint/detect_linux_exploit_suggester_execution.yml
pass_condition: '| stats count | where count > 0'
earliest_time: '-24h'
latest_time: 'now'
attack_data:
- file_name: linuxexploitsuggesterdatasets.txt
data: https://github.com/splunk/attack_data/raw/master/datasets/suspicious_behaviour/linux_post_exploitation/linuxexploitsuggesterdatasets.txt
source: "Syslog:Linux-Sysmon/Operational"
sourcetype: "sysmon_linux"
@@ -0,0 +1,12 @@
name: Detect MimiPenguin Unit Test
tests:
- name: Detect MimiPenguin
file: endpoint/detect_mimipenguin.yml
pass_condition: '| stats count | where count > 0'
earliest_time: '-24h'
latest_time: 'now'
attack_data:
- file_name: mimipenguin.txt
data: https://github.com/splunk/attack_data/raw/master/datasets/suspicious_behaviour/linux_post_exploitation/mimipenguin.txt
source: "Syslog:Linux-Sysmon/Operational"
sourcetype: "sysmon_linux"