Elastic Defend high stable eql
Network Connection Following Ptrace Manipulation
This rule detects a process attempting a network connection shortly after its memory or register state was modified by another process through ptrace. This behavior may indicate successful process injection followed by network activity from the injected payload.
Detection Logic
sequence with maxspan=3s
[process where event.type == "start" and event.action == "ptrace" and (
process.Ext.ptrace.request in (4, 5, 13, 16901) or
(process.Ext.ptrace.request == 6 and
process.Ext.ptrace.addr in (48, 60, 128, 152))
) and
not process.executable in ("/opt/traps/bin/dypdng", "/system/bin/app_process64")] by process.Ext.ptrace.child_pid
[network where event.type == "start" and event.action == "connection_attempted" and
not (destination.ip == null or destination.ip == "0.0.0.0" or cidrmatch(
destination.ip, "10.0.0.0/8", "127.0.0.0/8", "169.254.0.0/16", "172.16.0.0/12", "192.0.0.0/24", "192.0.0.0/29",
"192.0.0.8/32", "192.0.0.9/32", "192.0.0.10/32", "192.0.0.170/32", "192.0.0.171/32", "192.0.2.0/24",
"192.31.196.0/24", "192.52.193.0/24", "192.168.0.0/16", "192.88.99.0/24", "224.0.0.0/4", "100.64.0.0/10",
"192.175.48.0/24","198.18.0.0/15", "198.51.100.0/24", "203.0.113.0/24", "240.0.0.0/4", "::1", "FE80::/10",
"FF00::/8"
)
)] by process.pid Field Validations
Loading…
Comments (0)
Loading comments...