This website uses cookies to ensure you get the best experience.
Got it!
Register
|
Login
Menu
Home
Sigma Rules
Splunk Rules
Explore Rules
Analytic Stories
MITRE ATT&CK
Overview
Matrix
Techniques
Groups
Software
Campaigns
Search
About
Linux Base64 Encoded Pipe to Shell
Original Source:
[Sigma source]
Title:
Linux Base64 Encoded Pipe to Shell
Status:
test
Description:
Detects suspicious process command line that uses base64 encoded input for execution with a shell
References:
-https://github.com/arget13/DDexec
-https://www.mandiant.com/resources/blog/barracuda-esg-exploited-globally
Author:
pH-T (Nextron Systems)
Date:
2022-07-26
modified:
2023-06-16
Tags:
-'attack.stealth'
-'attack.t1140'
Logsource:
product: linux
category: process_creation
Detection:
selection_base64:
CommandLine|contains
:
'base64 '
selection_exec:
- CommandLine|contains
:
- '| bash '
- '| sh '
- '|bash '
- '|sh '
- CommandLine|endswith
:
- ' |sh'
- '| bash'
- '| sh'
- '|bash'
condition
:
all of selection_*
Falsepositives:
-Legitimate administration activities
Level:
medium