Analytics Story: Linux Post-Exploitation
Description
This analytic story identifies popular Linux post exploitation tools such as autoSUID, LinEnum, LinPEAS, Linux Exploit Suggesters, MimiPenguin.
Why it matters
These tools allow operators find possible exploits or paths for privilege escalation based on SUID binaries, user permissions, kernel version and distro version.
Detections
| Name ▲▼ |
Technique ▲▼ |
Type ▲▼ |
| Suspicious Linux Discovery Commands |
Unix Shell |
TTP |
| Linux Shell History Access Via Command Line Utility |
Shell History |
Anomaly |
| Linux Suspicious Child Process of PostgreSQL |
Exploit Public-Facing Application |
TTP |
| Linux Suspicious Privileged Container Execution |
Unix Shell, Deploy Container |
Anomaly |
| Linux Binary Executed from Shared Memory Directory |
Command and Scripting Interpreter |
Anomaly |
| Linux Suspicious GCC Invocation Building Init Shared Object |
Compile After Delivery, Exploitation for Privilege Escalation, Shared Modules, Stage Capabilities |
TTP |
| Linux Root Execution of id |
System Owner/User Discovery |
Anomaly |
| Windows Suspicious QEMU Execution |
Data Obfuscation, Masquerading, Malicious File, Run Virtual Instance |
TTP |
| Linux Possible Nimbuspwn Privilege Escalation |
Exploitation for Privilege Escalation |
TTP |
| Linux Suspicious Staging of Alternate System Files |
Masquerading |
Anomaly |
| Linux UDEV Rule Created |
Boot or Logon Initialization Scripts, Boot or Logon Autostart Execution |
Anomaly |
| Linux Possible Privilege Escalation via PYTHONPATH |
Exploitation for Privilege Escalation, Path Interception by PATH Environment Variable |
TTP |
| Linux MOTD Script Added |
Boot or Logon Initialization Scripts, Unix Shell, Boot or Logon Autostart Execution |
Anomaly |
| Linux Possible System Binary Backdoor |
Masquerading, Unix Shell |
Anomaly |
| Linux Shell Pseudo Device Reverse Shell |
Exfiltration Over Unencrypted Non-C2 Protocol, Command and Scripting Interpreter |
Anomaly |
| Linux Suspicious Redis Activity |
Exploitation of Remote Services, Server Software Component |
TTP |
| Linux Suspicious Docker Build Command Execution |
Deploy Container |
Anomaly |
| Linux Netcat Outbound Connection |
Unix Shell |
Anomaly |
| Linux Ghostscript Exploitation |
Command and Scripting Interpreter, Exploitation for Privilege Escalation, Malicious File, Phishing |
TTP |
| Linux Usermod Root UID Set |
Valid Accounts, Account Manipulation, Setuid and Setgid |
TTP |
| Linux Suspicious XDG Autostart |
Boot or Logon Initialization Scripts, Unix Shell, Boot or Logon Autostart Execution |
Anomaly |
Data Sources
References
Source: GitHub | Version: 2