Files
splunk-security_content/dev/endpoint/linux_curl_upload_file.yml
T
2023-01-20 13:24:15 +01:00

85 lines
2.9 KiB
YAML

name: Linux Curl Upload File
id: c1de2d9a-0c02-4bb4-a49a-510c6e9cf2bf
version: 1
date: '2022-07-29'
author: Michael Haag, Splunk
status: production
type: TTP
description: The following analytic identifies curl being utilized with the -F or
--form, --upload-file, -T, -d, --data, --data-raw, -I and --head switches to upload
AWS credentials or config to a remote destination. This enables uploading of binary
files and so forth. To force the 'content' part to be a file, prefix the file name
with an @ sign. To just get the content part from a file, prefix the file name with
the symbol <. The difference between @ and < is then that @ makes a file get attached
in the post as a file upload, while the < makes a text field and just get the contents
for that text field from a file. This technique was utlized by the TeamTNT group
to exfiltrate AWS credentials.
data_source:
- Sysmon Event ID 1
search:
selection1:
CommandLine:
- '*-F *'
- '*--form *'
- '*--upload-file *'
- '*-T *'
- '*-d *'
- '*--data *'
- '*--data-raw *'
- '*-I *'
- '*--head *'
Image|endswith: curl
selection2:
CommandLine: '*.aws/credentials*'
condition: selection1 and selection2
how_to_implement: To successfully implement this search you need to be ingesting information
on process that include the name of the process responsible for the changes from
your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition,
confirm the latest CIM App 4.20 or higher is installed and the latest TA for the
endpoint product.
known_false_positives: Filtering may be required. In addition to AWS credentials,
add other important files and monitor. The inverse would be to look for _all_ -F
behavior and tune from there.
references:
- https://curl.se/docs/manpage.html
- https://www.cadosecurity.com/team-tnt-the-first-crypto-mining-worm-to-steal-aws-credentials/
- https://gtfobins.github.io/gtfobins/curl/
tags:
analytic_story:
- Linux Living Off The Land
- Data Exfiltration
- Ingress Tool Transfer
asset_type: Endpoint
confidence: 80
impact: 80
message: An instance of $process_name$ was identified on endpoint $dest$ by user
$user$ attempting to upload important files to a remote destination.
mitre_attack_id:
- T1105
observable:
- name: user
type: User
role:
- Victim
- name: dest
type: Hostname
role:
- Victim
- name: process_name
type: Process
role:
- Child Process
product:
- Splunk Enterprise
- Splunk Enterprise Security
- Splunk Cloud
risk_score: 64
security_domain: endpoint
tests:
- name: True Positive Test
attack_data:
- data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1105/atomic_red_team/curl-linux-sysmon.log
source: Syslog:Linux-Sysmon/Operational
sourcetype: sysmon_linux
update_timestamp: true