This website uses cookies to ensure you get the best experience.
Got it!
Register
|
Login
Menu
Home
Sigma Rules
Splunk Rules
Explore Rules
Analytic Stories
MITRE ATT&CK
Overview
Matrix
Techniques
Groups
Software
Campaigns
Search
About
Suspicious Installer Package Child Process
Original Source:
[Sigma source]
Title:
Suspicious Installer Package Child Process
Status:
test
Description:
Detects the execution of suspicious child processes from macOS installer package parent process. This includes osascript, JXA, curl and wget amongst other interpreters
References:
-https://redcanary.com/blog/clipping-silver-sparrows-wings/
-https://github.com/elastic/detection-rules/blob/4312d8c9583be524578a14fe6295c3370b9a9307/rules/macos/execution_installer_package_spawned_network_event.toml
Author:
Sohan G (D4rkCiph3r)
Date:
2023-02-18
modified:
None
Tags:
-'attack.t1059'
-'attack.t1059.007'
-'attack.t1071'
-'attack.t1071.001'
-'attack.execution'
-'attack.command-and-control'
Logsource:
category: process_creation
product: macos
Detection:
selection_installer:
ParentImage|endswith
:
-'/package_script_service'
-'/installer'
Image|endswith
:
-'/sh'
-'/bash'
-'/dash'
-'/python'
-'/ruby'
-'/perl'
-'/php'
-'/javascript'
-'/osascript'
-'/tclsh'
-'/curl'
-'/wget'
CommandLine|contains
:
-'preinstall'
-'postinstall'
condition
:
selection_installer
Falsepositives:
-Legitimate software uses the scripts (preinstall, postinstall)
Level:
medium