Sigma medium experimental sigma

PUA - TruffleHog Execution - Linux

Detects execution of TruffleHog, a tool used to search for secrets in different platforms like Git, Jira, Slack, SharePoint, etc. that could be used maliciously. While it is a legitimate tool, intended for use in CI pipelines and security assessments, It was observed in the Shai-Hulud malware campaign targeting npm packages to steal sensitive information.

View Source

Detection Logic

{
  "selection_img": {
    "Image
| endswith": "/trufflehog"
  },
  "selection_cli_platform": {
    "CommandLine
| contains": [
      " docker --image ",
      " Git ",
      " GitHub ",
      " Jira ",
      " Slack ",
      " Confluence ",
      " SharePoint ",
      " s3 ",
      " gcs "
    ]
  },
  "selection_cli_verified": {
    "CommandLine
| contains": " --results=verified"
  },
  "condition": "selection_img or all of selection_cli_*"
}

False Positives

  • Legitimate use of TruffleHog by security teams or developers.

Field Validations

Loading…

Comments (0)

Loading comments...