Files
splunk-security_content/detections/endpoint/linux_proxy_socks_curl.yml
Michael Haag 8ad83a0b5f Haag It
Linux Curl Upload File
Linux Ingress Tool Transfer Hunting
Linux Ingress Tool Transfer with Curl
Linux Proxy Socks Curl
2022-07-29 11:17:19 -06:00

84 lines
3.6 KiB
YAML

name: Linux Proxy Socks Curl
id: bd596c22-ad1e-44fc-b242-817253ce8b08
version: 1
date: '2022-07-29'
author: Michael Haag, Splunk
type: TTP
datamodel:
- Endpoint
description: The following analytic identifies curl being utilized with a proxy based on command-line arguments - -x, socks, --preproxy and --proxy. This behavior is built into the MetaSploit Framework as a auxiliary module. What does socks buy an adversary?
SOCKS4a extends the SOCKS4 protocol to allow a client to specify a destination domain name rather than an IP address.
The SOCKS5 protocol is defined in RFC 1928. It is an incompatible extension of the SOCKS4 protocol; it offers more choices for authentication and adds support for IPv6 and UDP, the latter of which can be used for DNS lookups.
The protocols, and a proxy itself, allow an adversary to evade controls in place monitoring traffic, making it harder for the defender to identify and track activity.
search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time)
as lastTime from datamodel=Endpoint.Processes where Processes.process_name=curl
Processes.process IN ("*-x *", "*socks4a://*", "*socks5h://*", "*socks4://*","*socks5://*", "*--preproxy *", "--proxy*") by Processes.dest Processes.user Processes.parent_process_name Processes.process_name
Processes.process Processes.process_id Processes.parent_process_id
| `drop_dm_object_name(Processes)`
| `security_content_ctime(firstTime)`
| `security_content_ctime(lastTime)` | `linux_proxy_socks_curl_filter`'
how_to_implement: To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, confirm the latest CIM App 4.20 or higher is installed and the latest TA for the endpoint product.
known_false_positives: False positives may be present based on proxy usage internally. Filter as needed.
references:
- https://www.offensive-security.com/metasploit-unleashed/proxytunnels/
- https://curl.se/docs/manpage.html
- https://en.wikipedia.org/wiki/SOCKS
- https://oxylabs.io/blog/curl-with-proxy
- https://reqbin.com/req/c-ddxflki5/curl-proxy-server#:~:text=To%20use%20a%20proxy%20with,be%20URL%20decoded%20by%20Curl.
- https://gtfobins.github.io/gtfobins/curl/
tags:
analytic_story:
- Linux Living Off The Land
- Ingress Tool Transfer
asset_type: Endpoint
cis20:
- CIS 3
- CIS 5
- CIS 16
confidence: 80
context:
- Source:Endpoint
dataset:
- https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1105/atomic_red_team/curl-linux-sysmon.log
impact: 70
kill_chain_phases:
- Delivery
message: An instance of $process_name$ was identified
on endpoint $dest$ by user $user$ utilizing a proxy. Review activity for further details.
mitre_attack_id:
- T1090
- T1095
nist:
- DE.CM
observable:
- name: user
type: User
role:
- Victim
- name: dest
type: Hostname
role:
- Victim
- name: process_name
type: Process
role:
- Child Process
product:
- Splunk Enterprise
- Splunk Enterprise Security
- Splunk Cloud
required_fields:
- _time
- Processes.dest
- Processes.user
- Processes.parent_process_name #parent process name
- Processes.parent_process #parent cmdline
- Processes.original_file_name
- Processes.process_name #process name
- Processes.process #process cmdline
- Processes.process_id
- Processes.parent_process_path
- Processes.process_path
- Processes.parent_process_id
risk_score: 56
security_domain: endpoint