BPFDoor Abnormal Process ID or Lock File Accessed

 Original Source: [Sigma source]
Title: BPFDoor Abnormal Process ID or Lock File Accessed
Status: test
Description:detects BPFDoor .lock and .pid files access in temporary file storage facility
References:
  -https://www.sandflysecurity.com/blog/bpfdoor-an-evasive-linux-backdoor-technical-analysis/
  -https://www.elastic.co/security-labs/a-peek-behind-the-bpfdoor
  -https://www.rapid7.com/blog/post/tr-bpfdoor-telecom-networks-sleeper-cells-threat-research-report/
  -https://github.com/rapid7/Rapid7-Labs/blob/741c7196ec12a0a56b63463d1fd726ff14d3a97a/BPFDoor/rapid7_detect_bpfdoor.sh
Author: Rafal Piasecki
Date: 2022-08-10
modified:2026-03-30
Tags:
  • -'attack.execution'
  • -'attack.t1106'
  • -'attack.t1059'
Logsource:
  • product: linux
  • service: auditd
Detection:
  selection:
    type: 'PATH'
    name:
      -'/var/run/aepmonend.pid'
      -'/var/run/auditd.lock'
      -'/var/run/cma.lock'
      -'/var/run/console-kit.pid'
      -'/var/run/consolekit.pid'
      -'/var/run/daemon.pid'
      -'/var/run/hald-addon.pid'
      -'/var/run/hald-smartd.pid'
      -'/var/run/haldrund.pid'
      -'/var/run/hp-health.pid'
      -'/var/run/hpasmlit.lock'
      -'/var/run/hpasmlited.pid'
      -'/var/run/kdevrund.pid'
      -'/var/run/lldpad.lock'
      -'/var/run/mcelog.pid'
      -'/var/run/system.pid'
      -'/var/run/uvp-srv.pid'
      -'/var/run/vmtoolagt.pid'
      -'/var/run/xinetd.lock'

  condition:selection
Falsepositives:
  -Unlikely
Level: high