Elastic medium stable eql
Cloud Credential Search Detected via Defend for Containers
This rule detects the use of system search utilities like grep and find to search for AWS credentials inside a container. Unauthorized access to these sensitive files could lead to further compromise of the container environment or facilitate a container breakout to the underlying cloud environment.
Detection Logic
process where host.os.type == "linux" and event.type == "start" and event.action == "exec" and (
process.name in ("grep", "egrep", "fgrep", "find", "locate", "mlocate", "cat", "sed", "awk") or
(
/* Account for tools that execute utilities as a subprocess, in this case the target utility name will appear as a process arg */
process.name in ("bash", "dash", "sh", "tcsh", "csh", "zsh", "ksh", "fish", "busybox") and
process.args in (
"grep", "/bin/grep", "/usr/bin/grep", "/usr/local/bin/grep",
"egrep", "/bin/egrep", "/usr/bin/egrep", "/usr/local/bin/egrep",
"fgrep", "/bin/fgrep", "/usr/bin/fgrep", "/usr/local/bin/fgrep",
"find", "/bin/find", "/usr/bin/find", "/usr/local/bin/find",
"locate", "/bin/locate", "/usr/bin/locate", "/usr/local/bin/locate",
"mlocate", "/bin/mlocate", "/usr/bin/mlocate", "/usr/local/bin/mlocate",
"cat", "/bin/cat", "/usr/bin/cat", "/usr/local/bin/cat",
"sed", "/bin/sed", "/usr/bin/sed", "/usr/local/bin/sed",
"awk", "/bin/awk", "/usr/bin/awk", "/usr/local/bin/awk"
) and
/* default exclusion list to not FP on default multi-process commands */
not process.args in (
"which", "/bin/which", "/usr/bin/which", "/usr/local/bin/which",
"man", "/bin/man", "/usr/bin/man", "/usr/local/bin/man",
"chmod", "/bin/chmod", "/usr/bin/chmod", "/usr/local/bin/chmod",
"chown", "/bin/chown", "/usr/bin/chown", "/usr/local/bin/chown"
)
)
)
and
process.args like~ (
/* AWS Credentials */
"*aws_access_key_id*", "*aws_secret_access_key*", "*aws_session_token*", "*accesskeyid*", "*secretaccesskey*",
"*access_key*", "*.aws/credentials*",
/* Azure Credentials */
"*AZURE_CLIENT_ID*", "*AZURE_TENANT_ID*", "*AZURE_CLIENT_SECRET*", "*AZURE_FEDERATED_TOKEN_FILE*",
"*IDENTITY_ENDPOINT*", "*IDENTITY_HEADER*", "*MSI_ENDPOINT*", "*MSI_SECRET*",
"*/.azure/*", "*/var/run/secrets/azure/*",
/* GCP Credentials */
"*/.config/gcloud/*", "*application_default_credentials.json*",
"*type: service_account*", "*client_email*", "*private_key_id*", "*private_key*",
"*/var/run/secrets/google/*", "*GOOGLE_APPLICATION_CREDENTIALS*"
) and container.id like "*" Field Validations
Loading…
Comments (0)
Loading comments...