Linux Base64 Encoded Pipe to Shell

 Original Source: [Sigma source]
Title: Linux Base64 Encoded Pipe to Shell
Status: test
Description:Detects suspicious process command line that uses base64 encoded input for execution with a shell
References:
  -https://github.com/arget13/DDexec
  -https://www.mandiant.com/resources/blog/barracuda-esg-exploited-globally
Author: pH-T (Nextron Systems)
Date: 2022-07-26
modified:2023-06-16
Tags:
  • -'attack.stealth'
  • -'attack.t1140'
Logsource:
  • product: linux
  • category: process_creation
Detection:
  selection_base64:
    CommandLine|contains: 'base64 '
  selection_exec:
    - CommandLine|contains:
      - '| bash '
      - '| sh '
      - '|bash '
      - '|sh '
    - CommandLine|endswith:
      - ' |sh'
      - '| bash'
      - '| sh'
      - '|bash'
  condition:all of selection_*
Falsepositives:
  -Legitimate administration activities
Level: medium