Elastic high stable eql
Potential Privilege Escalation via Recently Compiled Executable
This rule monitors a sequence involving a program compilation event followed by its execution and a subsequent alteration of UID permissions to root privileges. This behavior can potentially indicate the execution of a kernel or software privilege escalation exploit.
Detection Logic
sequence by host.id with maxspan=1m
[process where host.os.type == "linux" and event.type == "start" and event.action == "exec" and
process.name in ("gcc", "g++", "cc") and user.id != "0"] by process.args
[file where host.os.type == "linux" and event.action == "creation" and event.type == "creation" and
process.name == "ld" and user.id != "0"] by file.name
[process where host.os.type == "linux" and event.type == "start" and event.action == "exec" and
user.id != "0"] by process.name
[process where host.os.type == "linux" and event.action in ("uid_change", "guid_change") and event.type == "change" and
user.id == "0"] by process.name Field Validations
Loading…
Comments (0)
Loading comments...