Techniques
Sample rules
Linux Binary Executed from Shared Memory Directory
- source: splunk
- technicques:
Description
The following analytic identifies the execution of a binary by root from Linux shared memory directories (/dev/shm/ and /run/shm/). Threat actors place executables in these directories to persist on high-uptime servers as system backdoors. Both /dev/shm and /run/shm are tmpfs-backed directories that exist only in virtual memory with no persistent storage, making them attractive for staging fileless or semi-fileless malware while avoiding disk forensics.
Detection logic
| tstats `security_content_summariesonly`
count min(_time) as firstTime
max(_time) as lastTime
from datamodel=Endpoint.Processes where
Processes.process_path IN (
"/dev/shm/*",
"/run/shm/*"
)
Processes.user=root
by Processes.process Processes.process_path Processes.process_name Processes.user
Processes.user_id Processes.process_hash Processes.parent_process_name
Processes.parent_process_path Processes.parent_process Processes.parent_process_guid
Processes.parent_process_id Processes.process_guid Processes.process_id
Processes.vendor_product Processes.action Processes.dest
Processes.process_current_directory Processes.process_integrity_level
Processes.original_file_name
| `drop_dm_object_name(Processes)`
| `security_content_ctime(firstTime)`
| `security_content_ctime(lastTime)`
| `linux_binary_executed_from_shared_memory_directory_filter`