Elastic medium stable eql
Payload Downloaded by Interpreter and Piped to Interpreter
This rule detects when a payload is downloaded by an interpreter, and piped to an interpreter. Attackers may use this technique to download and execute payloads for various malicious purposes, such as establishing persistence or exfiltrating data.
Detection Logic
sequence by host.id, process.parent.entity_id, process.working_directory with maxspan=1s
[network where host.os.type == "linux" and event.type == "start" and event.action == "connection_attempted" and (
process.name like (
"bash", "dash", "sh", "tcsh", "tclsh", "wish", "csh", "zsh", "ksh", "fish",
"mksh", "busybox", "rscript", "r", "julia", "mono", "dotnet", "groovy", "kotlin",
"scala", "erlang", "escript", "ocaml", "ocamlopt", "ld.so", "ld-linux-x86-64.so.2",
"ld-musl-x86_64.so.1", "awk", "gawk", "mawk", "nawk", "node", "nodejs", "deno",
"env", "timeout", "nice", "stdbuf", "setsid", "setarch", "unshare", "nsenter", "flock",
"runuser", "sudo", "snap"
) or
process.name like ("python*", "perl*", "ruby*", "lua*", "php*", "qemu-*-static")
) and
not (destination.ip == null or destination.ip == "0.0.0.0" or cidrmatch(
destination.ip, "10.0.0.0/8", "127.0.0.0/8", "169.254.0.0/16", "172.16.0.0/12", "192.0.0.0/24", "192.0.0.0/29",
"192.0.0.8/32", "192.0.0.9/32", "192.0.0.10/32", "192.0.0.170/32", "192.0.0.171/32", "192.0.2.0/24",
"192.31.196.0/24", "192.52.193.0/24", "192.168.0.0/16", "192.88.99.0/24", "224.0.0.0/4", "100.64.0.0/10",
"192.175.48.0/24","198.18.0.0/15", "198.51.100.0/24", "203.0.113.0/24", "240.0.0.0/4", "::1", "FE80::/10",
"FF00::/8"
)
)]
[process where host.os.type == "linux" and event.type == "start" and event.action == "exec" and (
process.name like (
"bash", "dash", "sh", "tcsh", "tclsh", "wish", "csh", "zsh", "ksh", "fish",
"mksh", "busybox", "rscript", "r", "julia", "mono", "dotnet", "groovy", "kotlin",
"scala", "erlang", "escript", "ocaml", "ocamlopt", "ld.so", "ld-linux-x86-64.so.2",
"ld-musl-x86_64.so.1", "awk", "gawk", "mawk", "nawk", "node", "nodejs", "deno"
) or
process.name like ("python*", "perl*", "ruby*", "lua*", "php*")
) and (
stringcontains(process.executable, process.command_line) or
stringcontains(process.name, process.command_line)
) and
process.args_count == 1] Field Validations
Loading…
Comments (0)
Loading comments...