System Information Discovery - Auditd

 Original Source: [Sigma source]
Title: System Information Discovery - Auditd
Status: test
Description:Detects System Information Discovery commands
References:
  -https://github.com/redcanaryco/atomic-red-team/blob/f296668303c29d3f4c07e42bdd2b28d8dd6625f9/atomics/T1082/T1082.md
Author: Pawel Mazur
Date: 2021-09-03
modified:2023-03-06
Tags:
  • -'attack.discovery'
  • -'attack.t1082'
Logsource:
  • product: linux
  • service: auditd
Detection:
  selection_1:
    type: 'PATH'
    name:
      -'/etc/lsb-release'
      -'/etc/redhat-release'
      -'/etc/issue'

  selection_2:
    type: 'EXECVE'
    a0:
      -'uname'
      -'uptime'
      -'lsmod'
      -'hostname'
      -'env'

  selection_3:
    type: 'EXECVE'
    a0: 'grep'
    a1|contains:
      -'vbox'
      -'vm'
      -'xen'
      -'virtio'
      -'hv'

  selection_4:
    type: 'EXECVE'
    a0: 'kmod'
    a1: 'list'
  condition:1 of selection_*
Falsepositives:
  -Likely
Level: low