Name:Python Site Hooks Creation During Package Installation id:efaf40f5-779f-4b48-a941-b7d1a7c931ed version:1 date:None author:Onur Mustafa Erdogan, Splunk status:production type:TTP Description:The following analytic detects the creation of a Python site hook file (`sitecustomize.py` or `usercustomize.py`) within a `site-packages`/`dist-packages` directory in conjunction with a package installation process.
Python's `site` module loads these hooks from directories on `sys.path` before Python is executed.
If an adversary manipulates or plants one of these files, they can hijack the Python environment and execute their payload with every Python invocation, achieving persistence on the victim endpoint.
The VIPERTUNNEL backdoor was reported to abuse site hooks in order to import and trigger DLL execution.
If confirmed malicious, this could result in arbitrary code execution every time Python is invoked on the compromised host. Data_source:
-Sysmon EventID 1 AND Sysmon EventID 11
search:`sysmon` EventID IN (1,11) ( process="* install *" OR ( action="created" file_path="*-packages\\*" file_path IN ("*sitecustomize.py", "*usercustomize.py") ) )
| stats count min(_time) as firstTime max(_time) as lastTime values(parent_process_id) as parent_process_id values(parent_process_path) as parent_process_path values(parent_process_name) as parent_process_name values(parent_process) as parent_process values(process_path) as process_path values(process_name) as process_name values(process) as process values(file_path) as file_path values(file_name) as file_name dc(EventID) as dc_event_id by dest source process_id
| search dc_event_id>1
| table firstTime lastTime parent_process_id parent_process_path parent_process_name parent_process process_id process_path process_name process file_path file_name dest source
how_to_implement:This detection requires Sysmon event logs. Configure your environment to ingest Sysmon process creation (EventID 1)
and file creation (EventID 11) events, ensuring that file creation events are collected for files with the .py
extension. Ingest the data via the appropriate Splunk Technology Add-on and normalize field names using the
Splunk Common Information Model (CIM). known_false_positives:Some legitimate tooling and environment managers create or modify `sitecustomize.py`/`usercustomize.py`
as part of normal setup. Investigate the file contents and parent process to determine legitimacy. References: -https://blog.talosintelligence.com/the-serpents-tongue-luring-the-python-out-of-its-den/ drilldown_searches: name:'View the detection results for - "$dest$"' search:'%original_detection_search% | search dest = "$dest$"' earliest_offset:'$info_min_time$' latest_offset:'$info_max_time$' name:'View risk events for the last 7 days for - "$dest$"' search:'| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$dest$") | stats count min(_time) as firstTime max(_time) as lastTime values(search_name) as "Search Name" values(risk_message) as "Risk Message" values(analyticstories) as "Analytic Stories" values(annotations._all) as "Annotations" values(annotations.mitre_attack.mitre_tactic) as "ATT&CK Tactics" by normalized_risk_object | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`' earliest_offset:'7d' latest_offset:'0' analytic_story:['Malicious Python Package Installation', 'Compromised Windows Host', 'Windows Persistence Techniques']