Title:OMIGOD SCX RunAsProvider ExecuteShellCommand Status:test Description:Rule to detect the use of the SCX RunAsProvider Invoke_ExecuteShellCommand to execute any UNIX/Linux command using the /bin/sh shell.
SCXcore, started as the Microsoft Operations Manager UNIX/Linux Agent, is now used in a host of products including
Microsoft Operations Manager, Microsoft Azure, and Microsoft Operations Management Suite.
References: -https://www.wiz.io/blog/omigod-critical-vulnerabilities-in-omi-azure -https://github.com/Azure/Azure-Sentinel/pull/3059 Author: Roberto Rodriguez (Cyb3rWard0g), OTR (Open Threat Research), MSTIC Date: 2021-10-15 modified:2022-10-05 Tags:
-'attack.privilege-escalation'
-'attack.initial-access'
-'attack.execution'
-'attack.t1068'
-'attack.t1190'
-'attack.t1203'
Logsource:
product: linux
category: process_creation
Detection: selection: User:
'root' LogonId:
'0' CurrentDirectory:
'/var/opt/microsoft/scx/tmp' CommandLine|contains:
'/bin/sh' condition:selection Falsepositives:
-Legitimate use of SCX RunAsProvider Invoke_ExecuteShellCommand. Level:high