mirror of
https://github.com/splunk/security_content
synced 2026-06-08 17:32:49 +00:00
104 lines
5.5 KiB
YAML
104 lines
5.5 KiB
YAML
name: Linux Auditd Unix Shell Configuration Modification
|
|
id: 66f737c6-3f7f-46ed-8e9b-cc0e5bf01f04
|
|
version: 11
|
|
creation_date: '2024-08-22'
|
|
modification_date: '2026-05-13'
|
|
author: Teoderick Contreras, Splunk
|
|
status: production
|
|
type: TTP
|
|
description: |
|
|
The following analytic detects suspicious access or modifications to Unix shell configuration files, which may indicate an attempt to alter system behavior or gain unauthorized access.
|
|
Unix shell configuration files, such as `.bashrc` or `.profile`, control user environment settings and command execution.
|
|
Unauthorized changes to these files can be used to execute malicious commands, escalate privileges, or hide malicious activities.
|
|
By monitoring for unusual or unauthorized modifications to shell configuration files, this analytic helps identify potential security threats, allowing security teams to respond quickly and mitigate risks.
|
|
Correlate this with related EXECVE or PROCTITLE events to identify the process or user responsible for the access or modification.
|
|
data_source:
|
|
- Linux Auditd Path
|
|
- Linux Auditd Cwd
|
|
search: |
|
|
`linux_auditd`
|
|
(type=PATH OR type=CWD)
|
|
| rex "msg=audit\([^)]*:(?<audit_id>\d+)\)"
|
|
|
|
| stats
|
|
values(type) as types
|
|
values(name) as names
|
|
values(nametype) as nametype
|
|
values(cwd) as cwd_list
|
|
values(_time) as event_times
|
|
by audit_id, host
|
|
|
|
| eval current_working_directory = coalesce(mvindex(cwd_list, 0), "N/A")
|
|
| eval candidate_paths = mvmap(names, if(match(names, "^/"), names, current_working_directory + "/" + names))
|
|
| eval matched_paths = mvfilter(match(candidate_paths, "/etc/profile|/etc/shells|/etc/profile\\.d/.*|/etc/bash\\.bashrc.*|/etc/bashrc|.*/zsh/zprofile|.*/zsh/zshrc|.*/zsh/zlogin|.*/zsh/zlogout|/etc/csh\\.cshrc.*|/etc/csh\\.login.*|/root/\\.bashrc.*|/root/\\.bash_profile.*|/root/\\.profile.*|/root/\\.zshrc.*|/root/\\.zprofile.*|/home/.*/\\.bashrc.*|/home/.*/\\.zshrc.*|/home/.*/\\.bash_profile.*|/home/.*/\\.zprofile.*|/home/.*/\\.profile.*|/home/.*/\\.bash_login.*|/home/.*/\\.bash_logout.*|/home/.*/\\.zlogin.*|/home/.*/\\.zlogout.*"))
|
|
| eval match_count = mvcount(matched_paths)
|
|
| eval reconstructed_path = mvindex(matched_paths, 0)
|
|
| eval e_time = mvindex(event_times, 0)
|
|
| where match_count > 0
|
|
| rename host as dest
|
|
|
|
| stats count min(e_time) as firstTime max(e_time) as lastTime
|
|
values(nametype) as nametype
|
|
by current_working_directory
|
|
reconstructed_path
|
|
match_count
|
|
dest
|
|
audit_id
|
|
|
|
| `security_content_ctime(firstTime)`
|
|
| `security_content_ctime(lastTime)`
|
|
| `linux_auditd_unix_shell_configuration_modification_filter`
|
|
how_to_implement: |
|
|
To implement this detection, the process begins by ingesting auditd
|
|
data, that consist SYSCALL, TYPE, EXECVE and PROCTITLE events, which captures command-line
|
|
executions and process details on Unix/Linux systems. These logs should be ingested
|
|
and processed using Splunk Add-on for Unix and Linux (https://splunkbase.splunk.com/app/833),
|
|
which is essential for correctly parsing and categorizing the data. The next step
|
|
involves normalizing the field names to match the field names set by the Splunk
|
|
Common Information Model (CIM) to ensure consistency across different data sources
|
|
and enhance the efficiency of data modeling and make sure the type=CWD record type is activate in your auditd configuration.
|
|
This approach enables effective monitoring and detection of linux endpoints where auditd is deployed.
|
|
known_false_positives: |
|
|
Administrator or network operator can use this application for automation purposes.
|
|
Please update the filter macros to remove false positives.
|
|
references:
|
|
- https://www.splunk.com/en_us/blog/security/deep-dive-on-persistence-privilege-escalation-technique-and-detection-in-linux-platform.html
|
|
- https://github.com/peass-ng/PEASS-ng/tree/master/linPEAS
|
|
drilldown_searches:
|
|
- name: View the detection results for - "$dest$"
|
|
search: '%original_detection_search% | search dest = "$dest$"'
|
|
earliest_offset: $info_min_time$
|
|
latest_offset: $info_max_time$
|
|
- name: View risk events for the last 7 days for - "$dest$"
|
|
search: '| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$dest$") | stats count min(_time) as firstTime max(_time) as lastTime values(search_name) as "Search Name" values(risk_message) as "Risk Message" values(analyticstories) as "Analytic Stories" values(annotations._all) as "Annotations" values(annotations.mitre_attack.mitre_tactic) as "ATT&CK Tactics" by normalized_risk_object | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`'
|
|
earliest_offset: 7d
|
|
latest_offset: "0"
|
|
finding:
|
|
title: A [$nametype$] event occurred on host - [$dest$] to modify the unix shell configuration file.
|
|
entity:
|
|
field: dest
|
|
type: system
|
|
score: 50
|
|
analytic_story:
|
|
- Linux Living Off The Land
|
|
- Linux Privilege Escalation
|
|
- Linux Persistence Techniques
|
|
- Compromised Linux Host
|
|
- QuietVault
|
|
asset_type: Endpoint
|
|
mitre_attack_id:
|
|
- T1546.004
|
|
product:
|
|
- Splunk Enterprise
|
|
- Splunk Enterprise Security
|
|
- Splunk Cloud
|
|
category: endpoint
|
|
security_domain: endpoint
|
|
tests:
|
|
- name: True Positive Test
|
|
attack_data:
|
|
- data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1546.004/linux_auditd_unix_shell_mod_config//linux_path_profile_d.log
|
|
source: auditd
|
|
sourcetype: auditd
|
|
test_type: unit
|