Analytics Story: Linux Post-Exploitation
Description
This analytic story identifies popular Linux post exploitation tools such as autoSUID, LinEnum, LinPEAS, Linux Exploit Suggesters, MimiPenguin.
Why it matters
These tools allow operators find possible exploits or paths for privilege escalation based on SUID binaries, user permissions, kernel version and distro version.
Detections
| Name ▲▼ |
Technique ▲▼ |
Type ▲▼ |
| Linux Root Execution of id |
System Owner/User Discovery |
Anomaly |
| Linux Possible Privilege Escalation via PYTHONPATH |
Exploitation for Privilege Escalation, Path Interception by PATH Environment Variable |
TTP |
| Suspicious Linux Discovery Commands |
Unix Shell |
TTP |
| Linux MOTD Script Added |
Boot or Logon Initialization Scripts, Unix Shell, Boot or Logon Autostart Execution |
Anomaly |
| Linux Ghostscript Exploitation |
Command and Scripting Interpreter, Exploitation for Privilege Escalation, Malicious File, Phishing |
TTP |
| Linux Netcat Outbound Connection |
Unix Shell |
Anomaly |
| Windows Suspicious QEMU Execution |
Data Obfuscation, Masquerading, Malicious File, Run Virtual Instance |
TTP |
| Linux UDEV Rule Created |
Boot or Logon Initialization Scripts, Boot or Logon Autostart Execution |
Anomaly |
| Linux Suspicious Staging of Alternate System Files |
Masquerading |
Anomaly |
| Linux Possible Nimbuspwn Privilege Escalation |
Exploitation for Privilege Escalation |
TTP |
| Linux Usermod Root UID Set |
Valid Accounts, Account Manipulation, Setuid and Setgid |
TTP |
| Linux Suspicious Docker Build Command Execution |
Deploy Container |
Anomaly |
| Linux Shell Pseudo Device Reverse Shell |
Exfiltration Over Unencrypted Non-C2 Protocol, Command and Scripting Interpreter |
Anomaly |
| Linux Suspicious XDG Autostart |
Boot or Logon Initialization Scripts, Unix Shell, Boot or Logon Autostart Execution |
Anomaly |
| Linux Suspicious GCC Invocation Building Init Shared Object |
Compile After Delivery, Exploitation for Privilege Escalation, Shared Modules, Stage Capabilities |
TTP |
| Linux Binary Executed from Shared Memory Directory |
Command and Scripting Interpreter |
Anomaly |
| Linux Suspicious Child Process of PostgreSQL |
Exploit Public-Facing Application |
TTP |
| Linux Shell History Access Via Command Line Utility |
Shell History |
Anomaly |
| Linux Suspicious Privileged Container Execution |
Unix Shell, Deploy Container |
Anomaly |
| Linux Possible System Binary Backdoor |
Masquerading, Unix Shell |
Anomaly |
| Linux Suspicious Redis Activity |
Exploitation of Remote Services, Server Software Component |
TTP |
Data Sources
References
Source: GitHub | Version: 2