Elastic low stable kql

Suspicious Proc Pseudo File System Enumeration

This rule monitors for a rapid enumeration of 25 different proc cmd, stat, and exe files, which suggests an abnormal activity pattern. Such behavior could be an indicator of a malicious process scanning or gathering information about running processes, potentially for reconnaissance, privilege escalation, or identifying vulnerable targets.

View Source

Detection Logic

host.os.type:linux and event.category:file and event.action:"opened-file" and 
file.path : (/proc/*/cmdline or /proc/*/stat or /proc/*/exe) and not process.name : (
  ps or netstat or landscape-sysin or w or pgrep or pidof or needrestart or apparmor_status
) and not process.parent.pid : 1

Field Validations

Loading…

Comments (0)

Loading comments...