Title:OMIGOD SCX RunAsProvider ExecuteScript Status:test Description:Rule to detect the use of the SCX RunAsProvider ExecuteScript to execute any UNIX/Linux script using the /bin/sh shell.
Script being executed gets created as a temp file in /tmp folder with a scx* prefix.
Then it is invoked from the following directory /etc/opt/microsoft/scx/conf/tmpdir/.
The file in that directory has the same prefix scx*. SCXcore, started as the Microsoft Operations Manager UNIX/Linux Agent, is now used in a host of products including
Microsoft Operations Manager, Microsoft Azure, and Microsoft Operations Management Suite.
References: -https://www.wiz.io/blog/omigod-critical-vulnerabilities-in-omi-azure -https://github.com/Azure/Azure-Sentinel/pull/3059 Author: Roberto Rodriguez (Cyb3rWard0g), OTR (Open Threat Research), MSTIC Date: 2021-10-15 modified:2022-10-05 Tags:
-'attack.privilege-escalation'
-'attack.initial-access'
-'attack.execution'
-'attack.t1068'
-'attack.t1190'
-'attack.t1203'
Logsource:
product: linux
category: process_creation
Detection: selection: User:
'root' LogonId:
'0' CurrentDirectory:
'/var/opt/microsoft/scx/tmp' CommandLine|contains:
'/etc/opt/microsoft/scx/conf/tmpdir/scx' condition:selection Falsepositives:
-Legitimate use of SCX RunAsProvider ExecuteScript. Level:high