Suspicious Invocation of Shell via AWK - Linux

 Original Source: [Sigma source]
Title: Suspicious Invocation of Shell via AWK - Linux
Status: test
Description:Detects the execution of "awk" or it's sibling commands, to invoke a shell using the system() function. This behavior is commonly associated with attempts to execute arbitrary commands or escalate privileges, potentially leading to unauthorized access or further exploitation.
References:
  -https://gtfobins.github.io/gtfobins/awk/#shell
  -https://gtfobins.github.io/gtfobins/gawk/#shell
  -https://gtfobins.github.io/gtfobins/nawk/#shell
  -https://gtfobins.github.io/gtfobins/mawk/#shell
Author: Li Ling, Andy Parkidomo, Robert Rakowski, Blake Hartstein (Bloomberg L.P.)
Date: 2024-09-02
modified:None
Tags:
  • -'attack.execution'
  • -'attack.t1059'
Logsource:
  • category: process_creation
  • product: linux
Detection:
  selection_img:
    Image|endswith:
      -'/awk'
      -'/gawk'
      -'/mawk'
      -'/nawk'

    CommandLine|contains: 'BEGIN {system'
  selection_cli:
    CommandLine|contains:
      -'/bin/bash'
      -'/bin/dash'
      -'/bin/fish'
      -'/bin/sh'
      -'/bin/zsh'

  condition:all of selection_*
Falsepositives:
  -Unknown
Level: high