Data Exfiltration with Wget

 Original Source: [Sigma source]
Title: Data Exfiltration with Wget
Status: test
Description:Detects attempts to post the file with the usage of wget utility. The adversary can bypass the permission restriction with the misconfigured sudo permission for wget utility which could allow them to read files like /etc/shadow.
References:
  -https://linux.die.net/man/1/wget
  -https://gtfobins.github.io/gtfobins/wget/
Author: Pawel Mazur
Date: 2021-11-18
modified:2022-12-25
Tags:
  • -'attack.exfiltration'
  • -'attack.t1048.003'
Logsource:
  • product: linux
  • service: auditd
Detection:
  selection:
    type: 'EXECVE'
    a0: 'wget'
    a1|startswith: '--post-file='
  condition:selection
Falsepositives:
  -Legitimate usage of wget utility to post a file
Level: medium