Elastic low stable eql
Sublime Plugin or Application Script Modification
Adversaries may create or modify the Sublime application plugins or scripts to execute a malicious payload each time the Sublime application is started.
Detection Logic
file where host.os.type == "macos" and event.action == "modification" and file.extension == "py" and
file.path like
(
"/Users/*/Library/Application Support/Sublime Text*/Packages/*.py",
"/Applications/Sublime Text.app/Contents/MacOS/sublime.py"
) and
not process.executable like
(
"/Applications/Sublime Text*.app/Contents/*",
"/usr/local/Cellar/git/*/bin/git",
"/Library/Developer/CommandLineTools/usr/bin/git",
"/usr/libexec/xpcproxy",
"/System/Library/PrivateFrameworks/DesktopServicesPriv.framework/Versions/A/Resources/DesktopServicesHelper"
) Field Validations
Loading…
Comments (0)
Loading comments...