Elastic Defend high stable eql

Network Connection Following Ptrace Manipulation

This rule detects a process attempting a network connection shortly after its memory or register state was modified by another process through ptrace. This behavior may indicate successful process injection followed by network activity from the injected payload.

View Source

Detection Logic

sequence with maxspan=3s
  [process where event.type == "start" and event.action == "ptrace" and (
    process.Ext.ptrace.request in (4, 5, 13, 16901) or
    (process.Ext.ptrace.request == 6 and
     process.Ext.ptrace.addr in (48, 60, 128, 152))
  ) and
  not process.executable in ("/opt/traps/bin/dypdng", "/system/bin/app_process64")] by process.Ext.ptrace.child_pid
  [network where event.type == "start" and event.action == "connection_attempted" and 
   not (destination.ip == null or destination.ip == "0.0.0.0" or cidrmatch(
     destination.ip, "10.0.0.0/8", "127.0.0.0/8", "169.254.0.0/16", "172.16.0.0/12", "192.0.0.0/24", "192.0.0.0/29",
     "192.0.0.8/32", "192.0.0.9/32", "192.0.0.10/32", "192.0.0.170/32", "192.0.0.171/32", "192.0.2.0/24",
     "192.31.196.0/24", "192.52.193.0/24", "192.168.0.0/16", "192.88.99.0/24", "224.0.0.0/4", "100.64.0.0/10",
     "192.175.48.0/24","198.18.0.0/15", "198.51.100.0/24", "203.0.113.0/24", "240.0.0.0/4", "::1", "FE80::/10",
     "FF00::/8"
     )
   )] by process.pid

Field Validations

Loading…

Comments (0)

Loading comments...