Files
splunk-security_content/detections/endpoint/linux_edit_cron_table_parameter.yml
T
2021-12-21 11:02:15 +01:00

70 lines
2.5 KiB
YAML

name: Linux Edit Cron Table Parameter
id: 0d370304-5f26-11ec-a4bb-acde48001122
version: 1
date: '2021-12-17'
author: Teoderick Contreras, Splunk
type: Hunting
datamodel:
- Endpoint
description: The following analytic identifies a suspicious edit cronjobs parameter.
This commandline parameter can be abuse by malware author, adversaries, and red red teamers to add cronjob entry to their malicious code to execute
to the schedule they want. This event can also be executed by administrator or normal user for automation purposes so filter is needed.
search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time)
as lastTime from datamodel=Endpoint.Processes
where Processes.process_name = crontab Processes.process = "*crontab *" Processes.process = "* -e*"
by Processes.dest Processes.user Processes.parent_process_name Processes.process_name Processes.process Processes.process_id Processes.parent_process_id
| `drop_dm_object_name(Processes)`
| `security_content_ctime(firstTime)`
| `security_content_ctime(lastTime)`
| `linux_edit_cron_table_parameter_filter`'
how_to_implement: To successfully implement this search, you need to be ingesting
logs with the process name, parent process, and command-line executions from your
endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the
Sysmon TA.
known_false_positives: Administrator or network operator can use this application for automation purposes. filter is needed
references:
- https://attack.mitre.org/techniques/T1053/003/
tags:
analytic_story:
- Linux Privilege Escalation
- Linux Persistence Techniques
dataset:
- https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1053.003/crontab_edit_parameter/sysmon_linux.log
kill_chain_phases:
- Privilege Escalation
mitre_attack_id:
- T1053.003
- T1053
product:
- Splunk Enterprise
- Splunk Enterprise Security
- Splunk Cloud
required_fields:
- _time
- Processes.dest
- Processes.user
- Processes.parent_process_name
- Processes.process_name
- Processes.process
- Processes.process_id
- Processes.parent_process_id
security_domain: endpoint
impact: 30
confidence: 30
# (impact * confidence)/100
risk_score: 9
context:
- source:endpoint
- stage:Privilege Escalation Persistence
message: a possible crontab edit command $process$ executed on $dest$
observable:
- name: dest
type: Hostname
role:
- Victim
nist:
- DE.CM
cis20:
- CIS 3
- CIS 5
- CIS 16