Techniques
Sample rules
Linux UDEV Rule Created
- source: splunk
- technicques:
Description
The following analytic detects the creation of files within udev rules directories, including /etc/udev/rules.d and /usr/lib/udev/rules.d. Adversaries abuse udev rules to achieve persistent code execution by embedding RUN+= directives that trigger arbitrary commands whenever a matching device event occurs, such as a USB device being connected or a network interface coming online. Because udev rules execute in the context of the udev daemon with elevated privileges, this technique can provide both persistence and privilege escalation. It is used by post-exploitation frameworks such as PANIX and is effective on headless servers where device events still fire despite no interactive user session.
Detection logic
| tstats `security_content_summariesonly`
count min(_time) as firstTime
max(_time) as lastTime
FROM datamodel=Endpoint.Filesystem WHERE
Filesystem.file_path IN (
"/etc/udev/rules.d/*",
"/usr/lib/udev/rules.d/*"
)
BY Filesystem.action Filesystem.dest Filesystem.file_access_time
Filesystem.file_create_time Filesystem.file_hash Filesystem.file_modify_time
Filesystem.file_name Filesystem.file_path Filesystem.process_guid
Filesystem.process_id Filesystem.user Filesystem.vendor_product
| `drop_dm_object_name(Filesystem)`
| `security_content_ctime(firstTime)`
| `security_content_ctime(lastTime)`
| `linux_udev_rule_created_filter`