Techniques
Sample rules
Linux MOTD Script Added
- source: splunk
- technicques:
Description
The following analytic detects the creation of a file within the /etc/update-motd.d directory. This is used to add scripts that run with Message of the Day (MOTD) when a user logs in. This can be used by attackers for persistence if it contains malicious code.
Detection logic
| tstats `security_content_summariesonly`
count min(_time) as firstTime
max(_time) as lastTime
from datamodel=Endpoint.Filesystem where
Filesystem.file_path="/etc/update-motd.d/*"
Filesystem.action IN ("created", "modified")
by Filesystem.file_path Filesystem.file_name
Filesystem.user Filesystem.dest
Filesystem.action Filesystem.process_guid
Filesystem.process_id
| `drop_dm_object_name(Filesystem)`
| `security_content_ctime(firstTime)`
| `security_content_ctime(lastTime)`
| `linux_motd_script_added_filter`