Elastic medium stable eql
System and Network Configuration Check
Detects when the SystemConfiguration preferences plist file is accessed by an unusual or suspicious process. This may indicate an attempt to gain situational awareness on a target system by reading network configuration details.
Detection Logic
file where host.os.type == "macos" and event.action == "open" and
file.path like "/Library/Preferences/SystemConfiguration/preferences.plist" and
(process.name like~ ("python*", "osascript", "perl", "ruby", "node") or
process.executable like ("/Users/Shared/*", "/tmp/*", "/private/tmp/*", "/var/tmp/*", "/private/var/tmp/*")) and
not Effective_process.executable like "/Applications/Docker.app/Contents/MacOS/Docker" Field Validations
Loading…
Comments (0)
Loading comments...