This website uses cookies to ensure you get the best experience.
Got it!
Register
|
Login
Menu
Home
Sigma Rules
Splunk Rules
Explore Rules
Analytic Stories
MITRE ATT&CK
Overview
Matrix
Techniques
Groups
Software
Campaigns
Search
About
System Information Discovery - Auditd
Original Source:
[Sigma source]
Title:
System Information Discovery - Auditd
Status:
test
Description:
Detects System Information Discovery commands
References:
-https://github.com/redcanaryco/atomic-red-team/blob/f296668303c29d3f4c07e42bdd2b28d8dd6625f9/atomics/T1082/T1082.md
Author:
Pawel Mazur
Date:
2021-09-03
modified:
2023-03-06
Tags:
-'attack.discovery'
-'attack.t1082'
Logsource:
product: linux
service: auditd
Detection:
selection_1:
type
:
'PATH'
name
:
-'/etc/lsb-release'
-'/etc/redhat-release'
-'/etc/issue'
selection_2:
type
:
'EXECVE'
a0
:
-'uname'
-'uptime'
-'lsmod'
-'hostname'
-'env'
selection_3:
type
:
'EXECVE'
a0
:
'grep'
a1|contains
:
-'vbox'
-'vm'
-'xen'
-'virtio'
-'hv'
selection_4:
type
:
'EXECVE'
a0
:
'kmod'
a1
:
'list'
condition
:
1 of selection_*
Falsepositives:
-Likely
Level:
low