Files
splunk-security_content/detections/endpoint/linux_pkexec_privilege_escalation.yml
2022-07-27 10:29:47 -06:00

89 lines
3.4 KiB
YAML

name: Linux pkexec Privilege Escalation
id: 03e22c1c-8086-11ec-ac2e-acde48001122
version: 1
date: '2022-01-28'
author: Michael Haag, Splunk
type: TTP
datamodel:
- Endpoint
description: The following analytic identifies `pkexec` spawning with no command-line
arguments. A vulnerability in Polkit's pkexec component identified as CVE-2021-4034
(PwnKit) which is present in the default configuration of all major Linux distributions
and can be exploited to gain full root privileges on the system.
search: '| tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Processes
where Processes.process_name=pkexec by _time Processes.dest Processes.process_id
Processes.parent_process_name Processes.process_name Processes.process Processes.process_path
| `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`
| regex process="(^.{1}$)" | `linux_pkexec_privilege_escalation_filter`'
how_to_implement: Depending on the EDR product in use, there are multiple ways to
"null" the command-line field, Processes.process. Two that may be useful `process="(^.{0}$)"`
or `| where isnull(process)`. To generate data for this behavior, Sysmon for Linux
was utilized. To successfully implement this search you need to be ingesting information
on process that include the name of the process responsible for the changes from
your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition,
confirm the latest CIM App 4.20 or higher is installed and the latest TA for the
endpoint product.
known_false_positives: False positives may be present, filter as needed.
references:
- https://www.reddit.com/r/crowdstrike/comments/sdfeig/20220126_cool_query_friday_hunting_pwnkit_local/
- https://linux.die.net/man/1/pkexec
- https://www.bleepingcomputer.com/news/security/linux-system-service-bug-gives-root-on-all-major-distros-exploit-released/
- https://access.redhat.com/security/security-updates/#/?q=polkit&p=1&sort=portal_publication_date%20desc&rows=10&portal_advisory_type=Security%20Advisory&documentKind=PortalProduct
tags:
analytic_story:
- Linux Privilege Escalation
- Linux Living Off The Land
confidence: 70
context:
- Source:Endpoint
- Stage:Defense Evasion
cve:
- CVE-2021-4034
dataset:
- https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1068/zoom_child_process/linux-sysmon.log
impact: 80
kill_chain_phases:
- Exploitation
message: An instance of $parent_process_name$ spawning $process_name$ was identified
on endpoint $dest$ by user $user$ related to a local privilege escalation in polkit
pkexec.
mitre_attack_id:
- T1068
observable:
- name: user
type: User
role:
- Victim
- name: dest
type: Hostname
role:
- Victim
- name: parent_process_name
type: Process
role:
- Parent Process
- name: process_name
type: Process
role:
- Child Process
product:
- Splunk Enterprise
- Splunk Enterprise Security
- Splunk Cloud
required_fields:
- _time
- Processes.dest
- Processes.user
- Processes.parent_process_name
- Processes.parent_process
- Processes.original_file_name
- Processes.process_name
- Processes.process
- Processes.process_id
- Processes.parent_process_path
- Processes.process_path
- Processes.parent_process_id
risk_score: 56
security_domain: endpoint
asset_type: Endpoint