Files
splunk-security_content/dev/endpoint/linux_doas_tool_execution.yml
T
2023-01-20 13:24:15 +01:00

58 lines
2.0 KiB
YAML

name: Linux Doas Tool Execution
id: d5a62490-6e09-11ec-884e-acde48001122
version: 1
date: '2022-01-05'
author: Teoderick Contreras, Splunk
status: production
type: Anomaly
description: This analytic is to detect the doas tool execution in linux host platform.
This utility tool allow standard users to perform tasks as root, the same way sudo
does. This tool is developed as a minimalistic alternative to sudo application.
This tool can be abused advesaries, attacker or malware to gain elevated privileges
to the targeted or compromised host. On the other hand this can also be executed
by administrator for a certain task that needs admin rights. In this case filter
is needed.
data_source:
- Sysmon Event ID 1
search:
selection1:
Image|endswith: doas
condition: selection1
how_to_implement: To successfully implement this search, you need to be ingesting
logs with the process name, parent process, and command-line executions from your
endpoints. If you are using Sysmon, you can use the Add-on for Linux Sysmon from
Splunkbase.
known_false_positives: Administrator or network operator can execute this command.
Please update the filter macros to remove false positives.
references:
- https://wiki.gentoo.org/wiki/Doas
- https://www.makeuseof.com/how-to-install-and-use-doas/
tags:
analytic_story:
- Linux Privilege Escalation
- Linux Persistence Techniques
asset_type: Endpoint
confidence: 70
impact: 70
message: A doas $process_name$ with commandline $process$ was executed on $dest$
mitre_attack_id:
- T1548.003
- T1548
observable:
- name: dest
type: Hostname
role:
- Victim
product:
- Splunk Enterprise
- Splunk Enterprise Security
- Splunk Cloud
risk_score: 49
security_domain: endpoint
tests:
- name: True Positive Test
attack_data:
- data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1548.003/doas_exec/sysmon_linux.log
source: Syslog:Linux-Sysmon/Operational
sourcetype: sysmon_linux