Techniques
Sample rules
Linux Shell History Access Via Command Line Utility
- source: splunk
- technicques:
Description
The following analytic detects attempts to read shell history files (bash, zsh, fish, etc.). A history file is a log file that records all the commands executed in a shell on a Linux or Unix-based operating system. A malicious actor who gains access to a user’s shell history file can potentially obtain sensitive information and use it to compromise the user’s system and data.
Detection logic
| tstats `security_content_summariesonly`
count min(_time) as firstTime
max(_time) as lastTime
from datamodel=Endpoint.Processes where
Processes.process_name IN (
"cat",
"fmt",
"head",
"less",
"more",
"nano",
"sort",
"tail",
"uniq",
"vi",
"vim"
)
Processes.process IN (
"*.bash_history*",
"*.history*",
"*.sh_history*",
"*.zhistory*",
"*.zsh_history*",
"*fish_history*"
)
by Processes.process Processes.vendor_product Processes.user_id Processes.process_hash
Processes.parent_process_name Processes.parent_process_exec Processes.action Processes.dest
Processes.process_current_directory Processes.process_path Processes.process_integrity_level
Processes.original_file_name Processes.parent_process Processes.parent_process_path
Processes.parent_process_guid Processes.parent_process_id Processes.process_guid
Processes.process_id Processes.user Processes.process_name
| `drop_dm_object_name(Processes)`
| `security_content_ctime(firstTime)`
| `security_content_ctime(lastTime)`
| `linux_shell_history_access_via_command_line_utility_filter`