name: Linux Shred Overwrite Command id: c1952cf1-643c-4965-82de-11c067cbae76 version: 1 date: '2022-04-22' author: Teoderick Contreras, Splunk status: production type: TTP description: This analytic is to detect a shred process to overwrite a files in a linux machine. Shred Linux application is designed to overwrite file to hide its contents or make the deleted file un-recoverable. Weve seen this technique in industroyer2 malware that tries to wipe energy facilities of targeted sector as part of its destructive attack. It might be some normal user may use this command for valid purposes but it is recommended to check what files, disk or folder it tries to shred that might be good pivot for incident response in this type of destructive malware. data_source: - Sysmon Event ID 1 search: selection1: CommandLine: - '*-n*' - '*-u*' - '*-z*' - '*-s*' Image|endswith: shred condition: selection1 how_to_implement: To successfully implement this search, you need to be ingesting logs with the process name, parent process, and command-line executions from your endpoints. If you are using Sysmon, you can use the Add-on for Linux Sysmon from Splunkbase. known_false_positives: Administrator or network operator can use this application for automation purposes. Please update the filter macros to remove false positives. references: - https://www.welivesecurity.com/2022/04/12/industroyer2-industroyer-reloaded/ - https://cert.gov.ua/article/39518 tags: analytic_story: - Industroyer2 - Linux Privilege Escalation - Linux Persistence Techniques asset_type: Endpoint confidence: 70 impact: 70 message: A possible shred overwrite command $process$ executed on $dest$ mitre_attack_id: - T1485 observable: - name: dest type: Hostname role: - Victim product: - Splunk Enterprise - Splunk Enterprise Security - Splunk Cloud risk_score: 49 security_domain: endpoint tests: - name: True Positive Test attack_data: - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1485/rm_shred_critical_dir/sysmon_linux.log source: Syslog:Linux-Sysmon/Operational sourcetype: sysmon:linux