Files
blue-team-tools/rules/linux/process_creation/proc_creation_lnx_hack_tools.yml
T
Feathers 8f6242c35f Update proc_creation_lnx_hack_tools.yml
added to the list of hacking tools, Linpeas, a privilege escalation script
2023-01-31 17:01:17 +01:00

41 lines
1.1 KiB
YAML

title: Linux HackTool Execution
id: a015e032-146d-4717-8944-7a1884122111
status: experimental
description: Detects known hacktool execution based on image name
references:
- Internal Research
- https://github.com/Gui774ume/ebpfkit
- https://github.com/pathtofile/bad-bpf
- https://github.com/carlospolop/PEASS-ng/releases/download/20221225/linpeas_linux_amd64
author: Nasreddine Bencherchali
date: 2023/01/03
modified: 2023/01/25
tags:
- attack.execution
logsource:
product: linux
category: process_creation
detection:
selection:
Image|endswith:
# Add more as you see fit
- '/sqlmap'
- '/teamserver'
- '/aircrack-ng'
- '/john'
- '/setoolkit'
- '/wpscan'
- '/hydra'
- '/nikto'
- '/linpeas_linux_amd64' #LINPEAS - a Linux-based privilege escalation script
# eBPF related malicious tools/poc's
- '/ebpfkit'
- '/bpfdos'
- '/exechijack'
- '/pidhide'
- '/writeblocker'
condition: selection
falsepositives:
- Unlikely
level: high