Files
splunk-security_content/dev/endpoint/linux_proxy_socks_curl.yml
2023-01-20 13:24:15 +01:00

84 lines
2.9 KiB
YAML

name: Linux Proxy Socks Curl
id: bd596c22-ad1e-44fc-b242-817253ce8b08
version: 1
date: '2022-07-29'
author: Michael Haag, Splunk
status: production
type: TTP
description: The following analytic identifies curl being utilized with a proxy based
on command-line arguments - -x, socks, --preproxy and --proxy. This behavior is
built into the MetaSploit Framework as a auxiliary module. What does socks buy an
adversary? SOCKS4a extends the SOCKS4 protocol to allow a client to specify a destination
domain name rather than an IP address. The SOCKS5 protocol is defined in RFC 1928.
It is an incompatible extension of the SOCKS4 protocol; it offers more choices for
authentication and adds support for IPv6 and UDP, the latter of which can be used
for DNS lookups. The protocols, and a proxy itself, allow an adversary to evade
controls in place monitoring traffic, making it harder for the defender to identify
and track activity.
data_source:
- Sysmon Event ID 1
search:
selection1:
CommandLine:
- '*-x *'
- '*socks4a://*'
- '*socks5h://*'
- '*socks4://*'
- '*socks5://*'
- '*--preproxy *'
- --proxy*
Image|endswith: curl
condition: selection1
how_to_implement: To successfully implement this search you need to be ingesting information
on process that include the name of the process responsible for the changes from
your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition,
confirm the latest CIM App 4.20 or higher is installed and the latest TA for the
endpoint product.
known_false_positives: False positives may be present based on proxy usage internally.
Filter as needed.
references:
- https://www.offensive-security.com/metasploit-unleashed/proxytunnels/
- https://curl.se/docs/manpage.html
- https://en.wikipedia.org/wiki/SOCKS
- https://oxylabs.io/blog/curl-with-proxy
- https://reqbin.com/req/c-ddxflki5/curl-proxy-server#:~:text=To%20use%20a%20proxy%20with,be%20URL%20decoded%20by%20Curl.
- https://gtfobins.github.io/gtfobins/curl/
tags:
analytic_story:
- Linux Living Off The Land
- Ingress Tool Transfer
asset_type: Endpoint
confidence: 80
impact: 70
message: An instance of $process_name$ was identified on endpoint $dest$ by user
$user$ utilizing a proxy. Review activity for further details.
mitre_attack_id:
- T1090
- T1095
observable:
- name: user
type: User
role:
- Victim
- name: dest
type: Hostname
role:
- Victim
- name: process_name
type: Process
role:
- Child Process
product:
- Splunk Enterprise
- Splunk Enterprise Security
- Splunk Cloud
risk_score: 56
security_domain: endpoint
tests:
- name: True Positive Test
attack_data:
- data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1105/atomic_red_team/curl-linux-sysmon.log
source: Syslog:Linux-Sysmon/Operational
sourcetype: sysmon_linux
update_timestamp: true