Shell Invocation via Apt - Linux

 Original Source: [Sigma source]
Title: Shell Invocation via Apt - Linux
Status: test
Description:Detects the use of the "apt" and "apt-get" commands to execute a shell or proxy commands. Such behavior may be associated with privilege escalation, unauthorized command execution, or to break out from restricted environments.
References:
  -https://gtfobins.github.io/gtfobins/apt/
  -https://gtfobins.github.io/gtfobins/apt-get/
Author: Nasreddine Bencherchali (Nextron Systems)
Date: 2022-12-28
modified:2024-09-02
Tags:
  • -'attack.discovery'
  • -'attack.t1083'
Logsource:
  • category: process_creation
  • product: linux
Detection:
  selection:
    Image|endswith:
      -'/apt'
      -'/apt-get'

    CommandLine|contains: 'APT::Update::Pre-Invoke::='
  condition:selection
Falsepositives:
  -Unknown
Level: medium