OMIGOD SCX RunAsProvider ExecuteScript

 Original Source: [Sigma source]
Title: OMIGOD SCX RunAsProvider ExecuteScript
Status: test
Description:Rule to detect the use of the SCX RunAsProvider ExecuteScript to execute any UNIX/Linux script using the /bin/sh shell. Script being executed gets created as a temp file in /tmp folder with a scx* prefix. Then it is invoked from the following directory /etc/opt/microsoft/scx/conf/tmpdir/. The file in that directory has the same prefix scx*. SCXcore, started as the Microsoft Operations Manager UNIX/Linux Agent, is now used in a host of products including Microsoft Operations Manager, Microsoft Azure, and Microsoft Operations Management Suite.
References:
  -https://www.wiz.io/blog/omigod-critical-vulnerabilities-in-omi-azure
  -https://github.com/Azure/Azure-Sentinel/pull/3059
Author: Roberto Rodriguez (Cyb3rWard0g), OTR (Open Threat Research), MSTIC
Date: 2021-10-15
modified:2022-10-05
Tags:
  • -'attack.privilege-escalation'
  • -'attack.initial-access'
  • -'attack.execution'
  • -'attack.t1068'
  • -'attack.t1190'
  • -'attack.t1203'
Logsource:
  • product: linux
  • category: process_creation
Detection:
  selection:
    User: 'root'
    LogonId: '0'
    CurrentDirectory: '/var/opt/microsoft/scx/tmp'
    CommandLine|contains: '/etc/opt/microsoft/scx/conf/tmpdir/scx'
  condition:selection
Falsepositives:
  -Legitimate use of SCX RunAsProvider ExecuteScript.
Level: high