Techniques
Sample rules
Linux File Creation In System Generator Directory
- source: splunk
- technicques:
Description
The following analytic detects potential persistence using a systemd generator on Linux, which involves creating a malicious script or binary that is typically executed during the system’s boot process. Systemd generators are typically placed in directories like /lib/systemd/system-generators/, where they are run early in the boot sequence to dynamically generate or modify unit files that control system services. By placing a custom generator in this directory, an attacker can ensure their code is executed each time the system starts, allowing them to maintain access or control even after reboots.
Detection logic
| tstats `security_content_summariesonly`
count min(_time) as firstTime
max(_time) as lastTime
from datamodel=Endpoint.Filesystem where
Filesystem.action IN ("created", "modified")
Filesystem.file_path="*/lib/systemd/system-generators/*"
by Filesystem.file_path Filesystem.file_name Filesystem.user Filesystem.dest
Filesystem.action Filesystem.process_guid Filesystem.process_id
| `drop_dm_object_name(Filesystem)`
| `security_content_ctime(firstTime)`
| `security_content_ctime(lastTime)`
| `linux_file_creation_in_system_generator_directory_filter`