Shell Execution via Rsync - Linux

 Original Source: [Sigma source]
Title: Shell Execution via Rsync - Linux
Status: experimental
Description:Detects the use of the "rsync" utility to execute a shell. Such behavior may be associated with privilege escalation, unauthorized command execution, or to break out from restricted environments.
References:
  -https://gtfobins.github.io/gtfobins/rsync/#shell
Author: Li Ling, Andy Parkidomo, Robert Rakowski, Blake Hartstein (Bloomberg L.P.), Florian Roth
Date: 2024-09-02
modified:2025-01-18
Tags:
  • -'attack.execution'
  • -'attack.t1059'
Logsource:
  • category: process_creation
  • product: linux
Detection:
  selection_img:
    Image|endswith:
      -'/rsync'
      -'/rsyncd'

    CommandLine|contains: ' -e '
  selection_cli:
    CommandLine|contains:
      -'/ash '
      -'/bash '
      -'/dash '
      -'/csh '
      -'/sh '
      -'/zsh '
      -'/tcsh '
      -'/ksh '
      -''ash '
      -''bash '
      -''dash '
      -''csh '
      -''sh '
      -''zsh '
      -''tcsh '
      -''ksh '

  condition:all of selection_*
Falsepositives:
  -Legitimate cases in which "rsync" is used to execute a shell
Level: high