System Information Discovery Using Ioreg

 Original Source: [Sigma source]
Title: System Information Discovery Using Ioreg
Status: test
Description:Detects the use of "ioreg" which will show I/O Kit registry information. This process is used for system information discovery. It has been observed in-the-wild by calling this process directly or using bash and grep to look for specific strings.
References:
  -https://www.virustotal.com/gui/file/0373d78db6c3c0f6f6dcc409821bf89e1ad8c165d6f95c5c80ecdce2219627d7/behavior
  -https://www.virustotal.com/gui/file/4ffdc72d1ff1ee8228e31691020fc275afd1baee5a985403a71ca8c7bd36e2e4/behavior
  -https://www.virustotal.com/gui/file/5907d59ec1303cfb5c0a0f4aaca3efc0830707d86c732ba6b9e842b5730b95dc/behavior
  -https://www.trendmicro.com/en_ph/research/20/k/new-macos-backdoor-connected-to-oceanlotus-surfaces.html
Author: Joseliyo Sanchez, @Joseliyo_Jstnk
Date: 2023-12-20
modified:2024-01-02
Tags:
  • -'attack.discovery'
  • -'attack.t1082'
Logsource:
  • product: macos
  • category: process_creation
Detection:
  selection_img:
Image|endswith:'/ioreg' CommandLine|contains:'ioreg'   selection_cmd1:
    CommandLine|contains:
      -'-l'
      -'-c'

  selection_cmd2:
    CommandLine|contains:
      -'AppleAHCIDiskDriver'
      -'IOPlatformExpertDevice'
      -'Oracle'
      -'Parallels'
      -'USB Vendor Name'
      -'VirtualBox'
      -'VMware'

  condition:all of selection_*
Falsepositives:
  -Legitimate administrative activities
Level: medium