Files
splunk-security_content/dev/endpoint/linux_cpulimit_privilege_escalation.yml
2024-06-26 14:41:53 +00:00

71 lines
2.1 KiB
YAML

name: Linux Cpulimit Privilege Escalation
id: d4e40b7e-aad3-4a7d-aac8-550ea5222be5
version: 1
date: '2022-08-11'
author: Gowthamaraj Rajendran, Splunk
status: production
type: Anomaly
description: cpulimit is a simple program which attempts to limit the cpu usage of
a process (expressed in percentage, not in cpu time). This is useful to control
batch jobs, when you don't want them to eat too much cpu. If sudo right is given
to the program for the user, then the user can run system commands as root and possibly
get a root shell.
data_source:
- Sysmon Event ID 1
search:
selection1:
CommandLine: '*-l*'
selection2:
CommandLine: '*cpulimit*'
selection3:
CommandLine: '*-f*'
selection4:
CommandLine: '*sudo*'
condition: selection1 and selection2 and selection3 and selection4
how_to_implement: To successfully implement this search, you need to be ingesting
logs with the process name, parent process, and command-line executions from your
endpoints into the Endpoint datamodel. If you are using Sysmon, you can use the
Add-on for Linux Sysmon from Splunkbase.
known_false_positives: False positives may be present, filter as needed.
references:
- https://gtfobins.github.io/gtfobins/cpulimit/
- http://cpulimit.sourceforge.net/
tags:
analytic_story:
- Linux Privilege Escalation
- Linux Living Off The Land
asset_type: Endpoint
confidence: 50
impact: 40
message: An instance of $parent_process_name$ spawning $process_name$ was identified
on endpoint $dest$
mitre_attack_id:
- T1548.003
- T1548
observable:
- name: dest
type: Hostname
role:
- Victim
- name: parent_process_name
type: Process
role:
- Parent Process
- name: process_name
type: Process
role:
- Child Process
product:
- Splunk Enterprise
- Splunk Enterprise Security
- Splunk Cloud
risk_score: 20
security_domain: endpoint
tests:
- name: True Positive Test
attack_data:
- data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1548/cpulimit/sysmon_linux.log
source: Syslog:Linux-Sysmon/Operational
sourcetype: sysmon:linux
update_timestamp: true