Binary Padding - Linux

 Original Source: [Sigma source]
Title: Binary Padding - Linux
Status: test
Description:Adversaries may use binary padding to add junk data and change the on-disk representation of malware. This rule detect using dd and truncate to add a junk data to file.
References:
  -https://github.com/redcanaryco/atomic-red-team/blob/f339e7da7d05f6057fdfcdd3742bfcf365fee2a9/atomics/T1027.001/T1027.001.md
Author: Igor Fits, oscd.community
Date: 2020-10-13
modified:2023-05-03
Tags:
  • -'attack.stealth'
  • -'attack.t1027.001'
Logsource:
  • product: linux
  • service: auditd
Detection:
  selection_execve:
    type: 'EXECVE'
  keywords_truncate:
    |all:
      -'truncate'
      -'-s'

  keywords_dd:
    |all:
      -'dd'
      -'if='

  keywords_filter:
    - 'of='
  condition:selection_execve and (keywords_truncate or (keywords_dd and not keywords_filter))
Falsepositives:
  -Unknown
Level: high