Elastic Defend high stable eql

Egress Network Connection from Default DPKG Directory

This rule monitors for network connections from processes that are executed from the /var/lib/dpkg/info/ directory. This directory is used to store information about installed packages. Attackers can backdoor the installation scripts of packages to establish network connections during the installation process to maintain persistence or to establish command and control.

View Source

Detection Logic

sequence with maxspan=3s
  [process where event.type == "start" and event.action == "exec" and
   process.parent.executable like "/var/lib/dpkg/info/*" and not (
     process.executable like ("/usr/sbin/runuser", "/opt/vivaldi/*", "/usr/bin/syslog-ng-update-virtualenv") or
     process.parent.executable == "/var/lib/dpkg/info/falco.postinst" or
     process.parent.executable like (
       "/var/lib/dpkg/info/percona-server-server-*.postinst", "/var/lib/dpkg/info/vivaldi*",
       "/var/lib/dpkg/info/percona-xtradb-cluster-server*", "/var/lib/dpkg/info/univention-updater*",
       "/var/lib/dpkg/info/microsoft-edge-beta.postinst"
     ) or
     process.parent.name in ("mdatp.postinst", "mdatp.postrm") or
     process.args like ("/var/lib/dpkg/info/percona-xtradb-cluster-server-*.postinst", "/etc/cron.daily/*")
   )
  ] by process.entity_id
  [network where event.type == "start" and event.action == "connection_attempted" and not (
   destination.ip == null or
   destination.ip == "0.0.0.0" or
   cidrmatch(
     destination.ip, "10.0.0.0/8", "127.0.0.0/8", "169.254.0.0/16", "172.16.0.0/12", "192.0.0.0/24", "192.0.0.0/29",
     "192.0.0.8/32", "192.0.0.9/32", "192.0.0.10/32", "192.0.0.170/32", "192.0.0.171/32", "192.0.2.0/24",
     "192.31.196.0/24", "192.52.193.0/24", "192.168.0.0/16", "192.88.99.0/24", "224.0.0.0/4", "100.64.0.0/10",
     "192.175.48.0/24","198.18.0.0/15", "198.51.100.0/24", "203.0.113.0/24", "240.0.0.0/4", "::1", "FE80::/10",
     "FF00::/8", "172.31.0.0/16"
     ) or
     process.executable in (
       "/usr/bin/apt-get", "/bin/apt-get", "/opt/cisco/amp/etc/ampinsthelper", "/opt/teleport/system/bin/tsh",
       "/usr/lib/apt/methods/https"
     )
   )] by process.parent.entity_id

Field Validations

Loading…

Comments (0)

Loading comments...