Files
splunk-security_content/dev/endpoint/linux_pkexec_privilege_escalation.yml
2023-01-20 13:24:15 +01:00

75 lines
2.7 KiB
YAML

name: Linux pkexec Privilege Escalation
id: 03e22c1c-8086-11ec-ac2e-acde48001122
version: 1
date: '2022-01-28'
author: Michael Haag, Splunk
status: production
type: TTP
description: The following analytic identifies `pkexec` spawning with no command-line
arguments. A vulnerability in Polkit's pkexec component identified as CVE-2021-4034
(PwnKit) which is present in the default configuration of all major Linux distributions
and can be exploited to gain full root privileges on the system.
data_source:
- Sysmon Event ID 1
search:
selection1:
Image|endswith: pkexec
condition: selection1
how_to_implement: Depending on the EDR product in use, there are multiple ways to
"null" the command-line field, Processes.process. Two that may be useful `process="(^.{0}$)"`
or `| where isnull(process)`. To generate data for this behavior, Sysmon for Linux
was utilized. To successfully implement this search you need to be ingesting information
on process that include the name of the process responsible for the changes from
your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition,
confirm the latest CIM App 4.20 or higher is installed and the latest TA for the
endpoint product.
known_false_positives: False positives may be present, filter as needed.
references:
- https://www.reddit.com/r/crowdstrike/comments/sdfeig/20220126_cool_query_friday_hunting_pwnkit_local/
- https://linux.die.net/man/1/pkexec
- https://www.bleepingcomputer.com/news/security/linux-system-service-bug-gives-root-on-all-major-distros-exploit-released/
- https://access.redhat.com/security/security-updates/#/?q=polkit&p=1&sort=portal_publication_date%20desc&rows=10&portal_advisory_type=Security%20Advisory&documentKind=PortalProduct
tags:
analytic_story:
- Linux Privilege Escalation
- Linux Living Off The Land
asset_type: Endpoint
confidence: 70
cve:
- CVE-2021-4034
impact: 80
message: An instance of $parent_process_name$ spawning $process_name$ was identified
on endpoint $dest$ by user $user$ related to a local privilege escalation in polkit
pkexec.
mitre_attack_id:
- T1068
observable:
- name: user
type: User
role:
- Victim
- name: dest
type: Hostname
role:
- Victim
- name: parent_process_name
type: Process
role:
- Parent Process
- name: process_name
type: Process
role:
- Child Process
product:
- Splunk Enterprise
- Splunk Enterprise Security
- Splunk Cloud
risk_score: 56
security_domain: endpoint
tests:
- name: True Positive Test
attack_data:
- data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1068/pkexec/linux-sysmon.log
source: Syslog:Linux-Sysmon/Operational
sourcetype: sysmon_linux