LoFP LoFP / legitimate system administrators or software installers may create udev rules as part of normal hardware configuration or device management tasks. filter based on known administrative activity and trusted software installations.

Techniques

Sample rules

Linux UDEV Rule Created

Description

The following analytic detects the creation of files within udev rules directories, including /etc/udev/rules.d and /usr/lib/udev/rules.d. Adversaries abuse udev rules to achieve persistent code execution by embedding RUN+= directives that trigger arbitrary commands whenever a matching device event occurs, such as a USB device being connected or a network interface coming online. Because udev rules execute in the context of the udev daemon with elevated privileges, this technique can provide both persistence and privilege escalation. It is used by post-exploitation frameworks such as PANIX and is effective on headless servers where device events still fire despite no interactive user session.

Detection logic


| tstats `security_content_summariesonly`
  count min(_time) as firstTime
        max(_time) as lastTime

FROM datamodel=Endpoint.Filesystem WHERE

Filesystem.file_path IN (
    "/etc/udev/rules.d/*",
    "/usr/lib/udev/rules.d/*"
)

BY Filesystem.action Filesystem.dest Filesystem.file_access_time
   Filesystem.file_create_time Filesystem.file_hash Filesystem.file_modify_time
   Filesystem.file_name Filesystem.file_path Filesystem.process_guid
   Filesystem.process_id Filesystem.user Filesystem.vendor_product


| `drop_dm_object_name(Filesystem)`

| `security_content_ctime(firstTime)`

| `security_content_ctime(lastTime)`

| `linux_udev_rule_created_filter`