This website uses cookies to ensure you get the best experience.
Got it!
Register
|
Login
Menu
Home
Sigma Rules
Splunk Rules
Explore Rules
Analytic Stories
MITRE ATT&CK
Overview
Matrix
Techniques
Groups
Software
Campaigns
Search
About
Unix Shell Configuration Modification
Original Source:
[Sigma source]
Title:
Unix Shell Configuration Modification
Status:
test
Description:
Detect unix shell configuration modification. Adversaries may establish persistence through executing malicious commands triggered when a new shell is opened.
References:
-https://objective-see.org/blog/blog_0x68.html
-https://web.archive.org/web/20221204161143/https://www.glitch-cat.com/p/green-lambert-and-attack
-https://www.anomali.com/blog/pulling-linux-rabbit-rabbot-malware-out-of-a-hat
Author:
Peter Matkovski, IAI
Date:
2023-03-06
modified:
2023-03-15
Tags:
-'attack.privilege-escalation'
-'attack.persistence'
-'attack.t1546.004'
Logsource:
product: linux
service: auditd
Detection:
selection:
type
:
'PATH'
name
:
-'/etc/shells'
-'/etc/profile'
-'/etc/profile.d/*'
-'/etc/bash.bashrc'
-'/etc/bashrc'
-'/etc/zsh/zprofile'
-'/etc/zsh/zshrc'
-'/etc/zsh/zlogin'
-'/etc/zsh/zlogout'
-'/etc/csh.cshrc'
-'/etc/csh.login'
-'/root/.bashrc'
-'/root/.bash_profile'
-'/root/.profile'
-'/root/.zshrc'
-'/root/.zprofile'
-'/home/*/.bashrc'
-'/home/*/.zshrc'
-'/home/*/.bash_profile'
-'/home/*/.zprofile'
-'/home/*/.profile'
-'/home/*/.bash_login'
-'/home/*/.bash_logout'
-'/home/*/.zlogin'
-'/home/*/.zlogout'
condition
:
selection
Falsepositives:
-Admin or User activity are expected to generate some false positives
Level:
medium