LoFP LoFP / custom postgresql extensions or wrapper scripts that legitimately invoke shell utilities may trigger this detection. baseline the environment and use the filter macro to suppress known-good parent/child combinations. recommend throttling by dest and process_name before enabling broadly.

Techniques

Sample rules

Linux Suspicious Child Process of PostgreSQL

Description

The following analytic detects PostgreSQL spawning a shell, interpreter, or network utility as a child process. When an attacker exploits a remote code execution vulnerability in PostgreSQL (such as via malicious COPY TO/FROM PROGRAM, CVE-2019-9193, or an insecurely configured extension), the database process itself becomes the parent of attacker-controlled commands. Legitimate PostgreSQL processes do not normally fork shells or download tools, making this a high-fidelity signal for post-exploitation activity.

Detection logic


| tstats `security_content_summariesonly`
  count min(_time) as firstTime
        max(_time) as lastTime

FROM datamodel=Endpoint.Processes WHERE

(
    Processes.parent_process_name IN (
        "postgres",
        "postmaster",
        "pg_ctl"
    )
    OR
    Processes.parent_process_path = "*/bin/postgres"
    OR
    Processes.process_current_directory="*/var/lib/postgresql/*/main*"
)
Processes.process_name IN (
    "awk", "bash", "curl", "dash", "env", "gawk", "id", "ifconfig",
    "ksh", "lua", "nc", "ncat", "netcat", "nmap", "openssl", "perl",
    "php", "python", "python2", "python3", "ruby", "sh", "socat",
    "tcpdump", "wget", "whoami", "zsh"
)

BY Processes.action Processes.dest Processes.original_file_name
   Processes.parent_process Processes.parent_process_exec Processes.parent_process_guid
   Processes.parent_process_id Processes.parent_process_name Processes.parent_process_path
   Processes.process Processes.process_current_directory Processes.process_exec
   Processes.process_guid Processes.process_hash Processes.process_id
   Processes.process_integrity_level Processes.process_name Processes.process_path
   Processes.user Processes.user_id Processes.vendor_product

| `drop_dm_object_name(Processes)`

| `security_content_ctime(firstTime)`

| `security_content_ctime(lastTime)`

| `linux_suspicious_child_process_of_postgresql_filter`