Elastic Defend high stable eql

Linux Powershell Egress Network Connection

Detects when Powershell (pwsh) on Linux makes an outbound network connection attempt. Powershell usage on Linux is rare, and leveraging Powershell to connect out to the internet may indicate malicious behavior.

View Source

Detection Logic

sequence by process.entity_id with maxspan=5s
  [process where event.type == "start" and event.action == "exec" and process.parent.name == "pwsh" and not (
    process.name in ("kubectl", "helm", "pwsh", "yum", "dnf", "dotnet", "ansible-lint") or
    process.executable like (
      "/run/containerd/*python3", "/jenkins-data/docker/*python3", "/tmp/Download-References/DepotDownloader/DepotDownloader",
      "/home/*/.local/bin/az", "/usr/libexec/platform-python*"
    ) or
    process.parent.executable like ("/jenkins-data/docker*", "/var/run/docker/*", "/run/containerd/*") or
    process.command_line == "/usr/bin/gh auth status" or
    (process.name like "python*" and process.args == "azure.cli") or
    process.working_directory like "/opt/azurevstsagent/agent*" or
    process.args == "/bin/dnf" or
    process.args like "/home/*/.local/bin/az"
  )
  ]
  [network where event.type == "start" and event.action == "connection_attempted" and not (
     destination.ip == null or
     destination.ip == "0.0.0.0" or
     cidrmatch(
       destination.ip, "10.0.0.0/8", "127.0.0.0/8", "169.254.0.0/16", "172.16.0.0/12", "192.0.0.0/24", "192.0.0.0/29",
       "192.0.0.8/32", "192.0.0.9/32", "192.0.0.10/32", "192.0.0.170/32", "192.0.0.171/32", "192.0.2.0/24",
       "192.31.196.0/24", "192.52.193.0/24", "192.168.0.0/16", "192.88.99.0/24", "224.0.0.0/4", "100.64.0.0/10",
       "192.175.48.0/24","198.18.0.0/15", "198.51.100.0/24", "203.0.113.0/24", "240.0.0.0/4", "::1", "FE80::/10",
       "FF00::/8"
     ) or
     process.name == "ssh"
   )
  ]

Field Validations

Loading…

Comments (0)

Loading comments...