fa27f1bc54
update: Elevated System Shell Spawned - Add `powershell_ise` fix: Potential Binary Or Script Dropper Via PowerShell - Add filter for `C:\Windows\SystemTemp\` fix: Python Initiated Connection - Enhance python filter fix: Conhost Spawned By Uncommon Parent Process - Add filter for `'-k wusvcs -p -s WaaSMedicSvc` update: Elevated System Shell Spawned From Uncommon Parent Location - Add `powershell_ise` fix: Potential WinAPI Calls Via CommandLine - Add new filter for `CompatTelRunner` fix: Windows Processes Suspicious Parent Directory - Add new filter for empty parent fix: Whoami.EXE Execution Anomaly - Add new filter for empty parent --------- Co-authored-by: Nasreddine Bencherchali <nasreddineb@splunk.com>
48 lines
2.4 KiB
YAML
48 lines
2.4 KiB
YAML
title: Python Initiated Connection
|
|
id: bef0bc5a-b9ae-425d-85c6-7b2d705980c6
|
|
status: test
|
|
description: Detects a Python process initiating a network connection. While this often relates to package installation, it can also indicate a potential malicious script communicating with a C&C server.
|
|
references:
|
|
- https://github.com/redcanaryco/atomic-red-team/blob/f339e7da7d05f6057fdfcdd3742bfcf365fee2a9/atomics/T1046/T1046.md#atomic-test-4---port-scan-using-python
|
|
- https://pypi.org/project/scapy/
|
|
author: frack113
|
|
date: 2021-12-10
|
|
modified: 2025-03-05
|
|
tags:
|
|
- attack.discovery
|
|
- attack.t1046
|
|
logsource:
|
|
category: network_connection
|
|
product: windows
|
|
definition: 'Requirements: Field enrichment is required for the filters to work. As field such as CommandLine and ParentImage are not available by default on this event type'
|
|
detection:
|
|
selection:
|
|
Initiated: 'true'
|
|
Image|contains|all:
|
|
- '\python'
|
|
- '.exe'
|
|
filter_optional_conda:
|
|
# Related to anaconda updates. Command example: "conda update conda"
|
|
# This filter will only work with aurora agent enriched data as Sysmon EID 3 doesn't contain CommandLine nor ParentImage
|
|
ParentImage: C:\ProgramData\Anaconda3\Scripts\conda.exe
|
|
CommandLine|contains|all:
|
|
- ':\ProgramData\Anaconda3\Scripts\conda-script.py'
|
|
- 'update'
|
|
filter_optional_conda_jupyter_notebook:
|
|
# Related to anaconda opening an instance of Jupyter Notebook
|
|
# This filter will only work with aurora agent enriched data as Sysmon EID 3 doesn't contain CommandLine nor ParentImage
|
|
ParentImage: C:\ProgramData\Anaconda3\python.exe
|
|
CommandLine|contains: 'C:\ProgramData\Anaconda3\Scripts\jupyter-notebook-script.py'
|
|
filter_main_local_communication:
|
|
# This could be caused when launching an instance of Jupyter Notebook locally for example but can also be caused by other instances of python opening sockets locally etc. So comment this out if you want to monitor for those instances
|
|
DestinationIp: 127.0.0.1
|
|
SourceIp: 127.0.0.1
|
|
filter_main_pip:
|
|
CommandLine|contains|all:
|
|
- 'pip.exe'
|
|
- 'install'
|
|
condition: selection and not 1 of filter_main_* and not 1 of filter_optional_*
|
|
falsepositives:
|
|
- Legitimate python scripts using the socket library or similar will trigger this. Apply additional filters and perform an initial baseline before deploying.
|
|
level: medium
|