mirror of
https://github.com/splunk/security_content
synced 2026-06-08 17:32:49 +00:00
8ad83a0b5f
Linux Curl Upload File Linux Ingress Tool Transfer Hunting Linux Ingress Tool Transfer with Curl Linux Proxy Socks Curl
81 lines
3.6 KiB
YAML
81 lines
3.6 KiB
YAML
name: Linux Curl Upload File
|
|
id: c1de2d9a-0c02-4bb4-a49a-510c6e9cf2bf
|
|
version: 1
|
|
date: '2022-07-29'
|
|
author: Michael Haag, Splunk
|
|
type: TTP
|
|
datamodel:
|
|
- Endpoint
|
|
description: The following analytic identifies curl being utilized with the -F or --form, --upload-file, -T, -d, --data, --data-raw, -I and --head switches to upload AWS credentials or config to a remote destination.
|
|
This enables uploading of binary files and so forth. To force the 'content' part to be a file, prefix the file name with an @ sign. To just get the content part from a file, prefix the file name with the symbol <. The difference between @ and < is then that @ makes a file get attached in the post as a file upload, while the < makes a text field and just get the contents for that text field from a file.
|
|
This technique was utlized by the TeamTNT group to exfiltrate AWS credentials.
|
|
search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time)
|
|
as lastTime from datamodel=Endpoint.Processes where Processes.process_name=curl
|
|
Processes.process IN ("*-F *", "*--form *","*--upload-file *","*-T *","*-d *","*--data *","*--data-raw *", "*-I *", "*--head *") AND Processes.process IN ("*.aws/credentials*". "*.aws/config*") by Processes.dest Processes.user Processes.parent_process_name Processes.process_name
|
|
Processes.process Processes.process_id Processes.parent_process_id
|
|
| `drop_dm_object_name(Processes)`
|
|
| `security_content_ctime(firstTime)`
|
|
| `security_content_ctime(lastTime)`
|
|
| `linux_curl_upload_file_filter`'
|
|
how_to_implement: To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, confirm the latest CIM App 4.20 or higher is installed and the latest TA for the endpoint product.
|
|
known_false_positives: Filtering may be required. In addition to AWS credentials, add other important files and monitor. The inverse would be to look for _all_ -F behavior and tune from there.
|
|
references:
|
|
- https://curl.se/docs/manpage.html
|
|
- https://www.cadosecurity.com/team-tnt-the-first-crypto-mining-worm-to-steal-aws-credentials/
|
|
- https://gtfobins.github.io/gtfobins/curl/
|
|
tags:
|
|
analytic_story:
|
|
- Linux Living Off The Land
|
|
- Data Exfiltration
|
|
- Ingress Tool Transfer
|
|
asset_type: Endpoint
|
|
cis20:
|
|
- CIS 3
|
|
- CIS 5
|
|
- CIS 16
|
|
confidence: 80
|
|
context:
|
|
- Source:Endpoint
|
|
dataset:
|
|
- https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1105/atomic_red_team/curl-linux-sysmon.log
|
|
impact: 80
|
|
kill_chain_phases:
|
|
- Actions on Objectives
|
|
message: An instance of $process_name$ was identified on endpoint $dest$ by user $user$ attempting to upload important files to a remote destination.
|
|
mitre_attack_id:
|
|
- T1105
|
|
nist:
|
|
- DE.CM
|
|
observable:
|
|
observable:
|
|
- name: user
|
|
type: User
|
|
role:
|
|
- Victim
|
|
- name: dest
|
|
type: Hostname
|
|
role:
|
|
- Victim
|
|
- name: process_name
|
|
type: Process
|
|
role:
|
|
- Child Process
|
|
product:
|
|
- Splunk Enterprise
|
|
- Splunk Enterprise Security
|
|
- Splunk Cloud
|
|
required_fields:
|
|
- _time
|
|
- Processes.dest
|
|
- Processes.user
|
|
- Processes.parent_process_name #parent process name
|
|
- Processes.parent_process #parent cmdline
|
|
- Processes.original_file_name
|
|
- Processes.process_name #process name
|
|
- Processes.process #process cmdline
|
|
- Processes.process_id
|
|
- Processes.parent_process_path
|
|
- Processes.process_path
|
|
- Processes.parent_process_id
|
|
risk_score: 64
|
|
security_domain: endpoint |