Suspicious Commands Linux

 Original Source: [Sigma source]
Title: Suspicious Commands Linux
Status: test
Description:Detects relevant commands often related to malware or hacking activity
References:
  -Internal Research - mostly derived from exploit code including code in MSF
Author: Florian Roth (Nextron Systems)
Date: 2017-12-12
modified:2022-10-05
Tags:
  • -'attack.execution'
  • -'attack.t1059.004'
Logsource:
  • product: linux
  • service: auditd
Detection:
  cmd1:
    type: 'EXECVE'
    a0: 'chmod'
    a1: '777'
  cmd2:
    type: 'EXECVE'
    a0: 'chmod'
    a1: 'u+s'
  cmd3:
    type: 'EXECVE'
    a0: 'cp'
    a1: '/bin/ksh'
  cmd4:
    type: 'EXECVE'
    a0: 'cp'
    a1: '/bin/sh'
  condition:1 of cmd*
Falsepositives:
  -Admin activity
Level: medium