Techniques
Sample rules
Linux Possible System Binary Backdoor
- source: splunk
- technicques:
Description
The following analytic detects the creation or overwrite of commonly targeted Linux system binaries such as cat, ls, cp, ps, mv, netstat, ss, and lsof. Adversaries may replace these utilities with backdoored versions to hide malicious activity, harvest credentials, or maintain persistence while appearing to use legitimate system tools. This technique is associated with rootkit deployment and post-exploitation frameworks such as PANIX.
Detection logic
| tstats `security_content_summariesonly`
count min(_time) as firstTime max(_time) as lastTime
from datamodel=Endpoint.Filesystem where
Filesystem.file_path IN (
"/usr/bin/cat",
"/usr/bin/cp",
"/usr/bin/ls",
"/usr/bin/lsof",
"/usr/bin/mv",
"/usr/bin/netstat",
"/usr/bin/ps",
"/usr/bin/ss"
)
by Filesystem.file_path Filesystem.file_name Filesystem.user Filesystem.dest
Filesystem.action Filesystem.process_guid Filesystem.process_id
| `drop_dm_object_name(Filesystem)`
| `security_content_ctime(firstTime)`
| `security_content_ctime(lastTime)`
| `linux_possible_system_binary_backdoor_filter`