Triple Cross eBPF Rootkit Default Persistence

 Original Source: [Sigma source]
Title: Triple Cross eBPF Rootkit Default Persistence
Status: test
Description:Detects the creation of "ebpfbackdoor" files in both "cron.d" and "sudoers.d" directories. Which both are related to the TripleCross persistence method
References:
  -https://github.com/h3xduck/TripleCross/blob/12629558b8b0a27a5488a0b98f1ea7042e76f8ab/apps/deployer.sh
Author: Nasreddine Bencherchali (Nextron Systems)
Date: 2022-07-05
modified:2022-12-31
Tags:
  • -'attack.privilege-escalation'
  • -'attack.execution'
  • -'attack.persistence'
  • -'attack.t1053.003'
Logsource:
  • product: linux
  • category: file_event
Detection:
  selection:
    TargetFilename|endswith: 'ebpfbackdoor'
  condition:selection
Falsepositives:
  -Unlikely
Level: high