Shell Execution GCC - Linux

 Original Source: [Sigma source]
Title: Shell Execution GCC - Linux
Status: test
Description:Detects the use of the "gcc" utility to execute a shell. Such behavior may be associated with privilege escalation, unauthorized command execution, or to break out from restricted environments.
References:
  -https://gtfobins.github.io/gtfobins/gcc/#shell
  -https://gtfobins.github.io/gtfobins/c89/#shell
  -https://gtfobins.github.io/gtfobins/c99/#shell
  -https://www.elastic.co/guide/en/security/current/linux-restricted-shell-breakout-via-linux-binary-s.html
Author: Li Ling, Andy Parkidomo, Robert Rakowski, Blake Hartstein (Bloomberg L.P.)
Date: 2024-09-02
modified:None
Tags:
  • -'attack.discovery'
  • -'attack.t1083'
Logsource:
  • category: process_creation
  • product: linux
Detection:
  selection_img:
    Image|endswith:
      -'/c89'
      -'/c99'
      -'/gcc'

    CommandLine|contains: '-wrapper'
  selection_cli:
    CommandLine|contains:
      -'/bin/bash,-s'
      -'/bin/dash,-s'
      -'/bin/fish,-s'
      -'/bin/sh,-s'
      -'/bin/zsh,-s'

  condition:all of selection_*
Falsepositives:
  -Unknown
Level: high