Analytics Story: Linux Post-Exploitation
Description
This analytic story identifies popular Linux post exploitation tools such as autoSUID, LinEnum, LinPEAS, Linux Exploit Suggesters, MimiPenguin.
Why it matters
These tools allow operators find possible exploits or paths for privilege escalation based on SUID binaries, user permissions, kernel version and distro version.
Detections
| Name ▲▼ |
Technique ▲▼ |
Type ▲▼ |
| Linux Binary Executed from Shared Memory Directory |
Command and Scripting Interpreter |
Anomaly |
| Linux Possible Privilege Escalation via PYTHONPATH |
Exploitation for Privilege Escalation, Path Interception by PATH Environment Variable |
TTP |
| Windows Suspicious QEMU Execution |
Data Obfuscation, Masquerading, Malicious File, Run Virtual Instance |
TTP |
| Linux Root Execution of id |
System Owner/User Discovery |
Anomaly |
| Suspicious Linux Discovery Commands |
Unix Shell |
TTP |
| Linux Netcat Outbound Connection |
Unix Shell |
Anomaly |
| Linux Suspicious Privileged Container Execution |
Unix Shell, Deploy Container |
Anomaly |
| Linux UDEV Rule Created |
Boot or Logon Initialization Scripts, Boot or Logon Autostart Execution |
Anomaly |
| Linux Suspicious Staging of Alternate System Files |
Masquerading |
Anomaly |
| Linux MOTD Script Added |
Boot or Logon Initialization Scripts, Unix Shell, Boot or Logon Autostart Execution |
Anomaly |
| Linux Suspicious GCC Invocation Building Init Shared Object |
Compile After Delivery, Exploitation for Privilege Escalation, Shared Modules, Stage Capabilities |
TTP |
| Linux Shell Pseudo Device Reverse Shell |
Exfiltration Over Unencrypted Non-C2 Protocol, Command and Scripting Interpreter |
Anomaly |
| Linux Possible System Binary Backdoor |
Masquerading, Unix Shell |
Anomaly |
| Linux Usermod Root UID Set |
Valid Accounts, Account Manipulation, Setuid and Setgid |
TTP |
| Linux Ghostscript Exploitation |
Command and Scripting Interpreter, Exploitation for Privilege Escalation, Malicious File, Phishing |
TTP |
| Linux Possible Nimbuspwn Privilege Escalation |
Exploitation for Privilege Escalation |
TTP |
| Linux Suspicious Redis Activity |
Exploitation of Remote Services, Server Software Component |
TTP |
| Linux Suspicious Child Process of PostgreSQL |
Exploit Public-Facing Application |
TTP |
| Linux Suspicious Docker Build Command Execution |
Deploy Container |
Anomaly |
| Linux Suspicious XDG Autostart |
Boot or Logon Initialization Scripts, Unix Shell, Boot or Logon Autostart Execution |
Anomaly |
| Linux Shell History Access Via Command Line Utility |
Shell History |
Anomaly |
Data Sources
References
Source: GitHub | Version: 2