mirror of
https://github.com/splunk/security_content
synced 2026-06-08 17:32:49 +00:00
19 lines
726 B
YAML
19 lines
726 B
YAML
name: Linux Post-Exploitation
|
|
id: d310ccfe-5477-11ec-ad05-acde48001122
|
|
version: 2
|
|
creation_date: '2021-12-03'
|
|
modification_date: '2026-05-13'
|
|
author: Rod Soto
|
|
status: production
|
|
description: This analytic story identifies popular Linux post exploitation tools such as autoSUID, LinEnum, LinPEAS, Linux Exploit Suggesters, MimiPenguin.
|
|
narrative: These tools allow operators find possible exploits or paths for privilege escalation based on SUID binaries, user permissions, kernel version and distro version.
|
|
references:
|
|
- https://attack.mitre.org/matrices/enterprise/linux/
|
|
category:
|
|
- Adversary Tactics
|
|
product:
|
|
- Splunk Enterprise
|
|
- Splunk Enterprise Security
|
|
- Splunk Cloud
|
|
usecase: Security Monitoring
|