Name:Python Network Traffic During Package Build id:03c9c504-2294-44da-8180-beefe1ca8ba8 version:1 date:None author:Onur Mustafa Erdogan, Splunk status:production type:Anomaly Description:The following analytic detects a Python process making an outbound network connection during package installation.
Adversaries can abuse `setup.py` build scripts by leveraging `distutils`/`setuptools` command classes to execute arbitrary code, including network beacons to third-party domains, the moment a malicious Python package is installed.
This activity is significant because it allows adversaries to establish a foothold or exfiltrate data without any direct interaction from the victim beyond running `pip install`.
If confirmed malicious, this could indicate a successful software supply chain compromise. Data_source:
-Sysmon EventID 1 AND Sysmon EventID 3
search:`sysmon` ( EventID=1 ( process="*_in_process.py*" OR process_name=python.exe ) ) OR ( EventID=3 dest_ip!="" process_name=python.exe )
| eval dest=if(EventID=3, Computer, dest)
| stats count min(_time) as firstTime max(_time) as lastTime values(parent_process_id) as parent_process_id values(parent_process_path) as parent_process_path values(parent_process_name) as parent_process_name values(parent_process) as parent_process values(process_path) as process_path values(process_name) as process_name values(process) as process values(dest_ip) as dest_ip values(dest_host) as dest_host
by dest source process_id
| search process="* build_wheel*" dest_ip=*
| table firstTime lastTime parent_process_id parent_process_path parent_process_name parent_process process_id process_path process_name process dest_ip dest_host dest source
how_to_implement:The detection is based on data that originates from Sysmon. To implement this search, you must ingest logs
with process creation (EventID 1) and network connection (EventID 3) events, mapped via the appropriate
Splunk Technology Add-on. Use the Splunk Common Information Model (CIM) to normalize the field names. known_false_positives:Python packages may contact software repositories, mirror sites during build time.
Investigate the destination and package content to determine legitimacy. References: -https://blog.talosintelligence.com/the-serpents-tongue-luring-the-python-out-of-its-den/ drilldown_searches: name:'View the detection results for - "$dest$"' search:'%original_detection_search% | search dest = "$dest$"' earliest_offset:'$info_min_time$' latest_offset:'$info_max_time$' name:'View risk events for the last 7 days for - "$dest$"' search:'| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$dest$") | stats count min(_time) as firstTime max(_time) as lastTime values(search_name) as "Search Name" values(risk_message) as "Risk Message" values(analyticstories) as "Analytic Stories" values(annotations._all) as "Annotations" values(annotations.mitre_attack.mitre_tactic) as "ATT&CK Tactics" by normalized_risk_object | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`' earliest_offset:'7d' latest_offset:'0' analytic_story:['Malicious Python Package Installation', 'Ingress Tool Transfer', 'Command And Control', 'Compromised Windows Host']