mirror of
https://github.com/splunk/security_content
synced 2026-06-08 17:32:49 +00:00
76 lines
2.7 KiB
YAML
76 lines
2.7 KiB
YAML
name: Linux Make Privilege Escalation
|
|
id: 80b22836-5091-4944-80ee-f733ac443f4f
|
|
version: 1
|
|
date: '2022-08-09'
|
|
author: Gowthamaraj Rajendran, Splunk
|
|
type: Anomaly
|
|
datamodel:
|
|
- Endpoint
|
|
description: The Linux make command is used to build and maintain groups of programs and files from the source code. In Linux, it is one of the most frequently used commands by the developers.
|
|
It assists developers to install and compile many utilities from the terminal.
|
|
If sudo right is given to make utility for the user, then the user can run system commands as root and possibly get a root shell.
|
|
search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time)
|
|
as lastTime from datamodel=Endpoint.Processes where Processes.process="*make*-s*" AND Processes.process="*--eval*" AND Processes.process="*sudo*" by Processes.dest Processes.user Processes.parent_process_name
|
|
Processes.process_name Processes.process Processes.process_id Processes.parent_process_id
|
|
Processes.process_guid | `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)`
|
|
| `security_content_ctime(lastTime)` | `linux_make_privilege_escalation_filter`'
|
|
how_to_implement: To successfully implement this search, you need to be ingesting
|
|
logs with the process name, parent process, and command-line executions from your
|
|
endpoints into the Endpoint datamodel. If you are using Sysmon, you can use the Add-on for Linux Sysmon from
|
|
Splunkbase.
|
|
known_false_positives: False positives may be present, filter as needed.
|
|
references:
|
|
- https://gtfobins.github.io/gtfobins/make/
|
|
- https://www.javatpoint.com/linux-make-command
|
|
tags:
|
|
analytic_story:
|
|
- Linux Privilege Escalation
|
|
- Linux Living Off The Land
|
|
asset_type: Endpoint
|
|
cis20:
|
|
- CIS 3
|
|
- CIS 5
|
|
- CIS 16
|
|
confidence: 50
|
|
context:
|
|
- Source:Endpoint
|
|
- Stage:Privilege Escalation
|
|
dataset:
|
|
- https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1548/make/sysmon_linux.log
|
|
impact: 40
|
|
kill_chain_phases:
|
|
- Exploitation
|
|
message: An instance of $parent_process_name$ spawning $process_name$ was identified on endpoint $dest$
|
|
mitre_attack_id:
|
|
- T1548.003
|
|
- T1548
|
|
nist:
|
|
- DE.CM
|
|
observable:
|
|
- name: dest
|
|
type: Hostname
|
|
role:
|
|
- Victim
|
|
- name: parent_process_name
|
|
type: Process
|
|
role:
|
|
- Parent Process
|
|
- name: process_name
|
|
type: Process
|
|
role:
|
|
- Child Process
|
|
product:
|
|
- Splunk Enterprise
|
|
- Splunk Enterprise Security
|
|
- Splunk Cloud
|
|
required_fields:
|
|
- _time
|
|
- Processes.dest
|
|
- Processes.user
|
|
- Processes.parent_process_name
|
|
- Processes.process_name
|
|
- Processes.process
|
|
- Processes.process_id
|
|
- Processes.parent_process_id
|
|
risk_score: 20
|
|
security_domain: endpoint |