Sigma medium experimental sigma
PUA - TruffleHog Execution - Linux
Detects execution of TruffleHog, a tool used to search for secrets in different platforms like Git, Jira, Slack, SharePoint, etc. that could be used maliciously. While it is a legitimate tool, intended for use in CI pipelines and security assessments, It was observed in the Shai-Hulud malware campaign targeting npm packages to steal sensitive information.
Detection Logic
{
"selection_img": {
"Image
| endswith": "/trufflehog"
},
"selection_cli_platform": {
"CommandLine
| contains": [
" docker --image ",
" Git ",
" GitHub ",
" Jira ",
" Slack ",
" Confluence ",
" SharePoint ",
" s3 ",
" gcs "
]
},
"selection_cli_verified": {
"CommandLine
| contains": " --results=verified"
},
"condition": "selection_img or all of selection_cli_*"
} False Positives
- ⚠ Legitimate use of TruffleHog by security teams or developers.
Field Validations
Loading…
Comments (0)
Loading comments...