Techniques
Sample rules
Linux Suspicious Child Process of PostgreSQL
- source: splunk
- technicques:
Description
The following analytic detects PostgreSQL spawning a shell, interpreter, or network utility as a child process. When an attacker exploits a remote code execution vulnerability in PostgreSQL (such as via malicious COPY TO/FROM PROGRAM, CVE-2019-9193, or an insecurely configured extension), the database process itself becomes the parent of attacker-controlled commands. Legitimate PostgreSQL processes do not normally fork shells or download tools, making this a high-fidelity signal for post-exploitation activity.
Detection logic
| tstats `security_content_summariesonly`
count min(_time) as firstTime
max(_time) as lastTime
FROM datamodel=Endpoint.Processes WHERE
(
Processes.parent_process_name IN (
"postgres",
"postmaster",
"pg_ctl"
)
OR
Processes.parent_process_path = "*/bin/postgres"
OR
Processes.process_current_directory="*/var/lib/postgresql/*/main*"
)
Processes.process_name IN (
"awk", "bash", "curl", "dash", "env", "gawk", "id", "ifconfig",
"ksh", "lua", "nc", "ncat", "netcat", "nmap", "openssl", "perl",
"php", "python", "python2", "python3", "ruby", "sh", "socat",
"tcpdump", "wget", "whoami", "zsh"
)
BY Processes.action Processes.dest Processes.original_file_name
Processes.parent_process Processes.parent_process_exec Processes.parent_process_guid
Processes.parent_process_id Processes.parent_process_name Processes.parent_process_path
Processes.process Processes.process_current_directory Processes.process_exec
Processes.process_guid Processes.process_hash Processes.process_id
Processes.process_integrity_level Processes.process_name Processes.process_path
Processes.user Processes.user_id Processes.vendor_product
| `drop_dm_object_name(Processes)`
| `security_content_ctime(firstTime)`
| `security_content_ctime(lastTime)`
| `linux_suspicious_child_process_of_postgresql_filter`