Suspicious Installer Package Child Process

 Original Source: [Sigma source]
Title: Suspicious Installer Package Child Process
Status: test
Description:Detects the execution of suspicious child processes from macOS installer package parent process. This includes osascript, JXA, curl and wget amongst other interpreters
References:
  -https://redcanary.com/blog/clipping-silver-sparrows-wings/
  -https://github.com/elastic/detection-rules/blob/4312d8c9583be524578a14fe6295c3370b9a9307/rules/macos/execution_installer_package_spawned_network_event.toml
Author: Sohan G (D4rkCiph3r)
Date: 2023-02-18
modified:None
Tags:
  • -'attack.t1059'
  • -'attack.t1059.007'
  • -'attack.t1071'
  • -'attack.t1071.001'
  • -'attack.execution'
  • -'attack.command-and-control'
Logsource:
  • category: process_creation
  • product: macos
Detection:
  selection_installer:
    ParentImage|endswith:
      -'/package_script_service'
      -'/installer'

    Image|endswith:
      -'/sh'
      -'/bash'
      -'/dash'
      -'/python'
      -'/ruby'
      -'/perl'
      -'/php'
      -'/javascript'
      -'/osascript'
      -'/tclsh'
      -'/curl'
      -'/wget'

    CommandLine|contains:
      -'preinstall'
      -'postinstall'

  condition:selection_installer
Falsepositives:
  -Legitimate software uses the scripts (preinstall, postinstall)
Level: medium