OMIGOD SCX RunAsProvider ExecuteShellCommand

 Original Source: [Sigma source]
Title: OMIGOD SCX RunAsProvider ExecuteShellCommand
Status: test
Description:Rule to detect the use of the SCX RunAsProvider Invoke_ExecuteShellCommand to execute any UNIX/Linux command using the /bin/sh shell. SCXcore, started as the Microsoft Operations Manager UNIX/Linux Agent, is now used in a host of products including Microsoft Operations Manager, Microsoft Azure, and Microsoft Operations Management Suite.
References:
  -https://www.wiz.io/blog/omigod-critical-vulnerabilities-in-omi-azure
  -https://github.com/Azure/Azure-Sentinel/pull/3059
Author: Roberto Rodriguez (Cyb3rWard0g), OTR (Open Threat Research), MSTIC
Date: 2021-10-15
modified:2022-10-05
Tags:
  • -'attack.privilege-escalation'
  • -'attack.initial-access'
  • -'attack.execution'
  • -'attack.t1068'
  • -'attack.t1190'
  • -'attack.t1203'
Logsource:
  • product: linux
  • category: process_creation
Detection:
  selection:
    User: 'root'
    LogonId: '0'
    CurrentDirectory: '/var/opt/microsoft/scx/tmp'
    CommandLine|contains: '/bin/sh'
  condition:selection
Falsepositives:
  -Legitimate use of SCX RunAsProvider Invoke_ExecuteShellCommand.
Level: high