LoFP LoFP / legitimate use of ghostscript for document processing or file conversion tasks may trigger this rule. filter based on known authorized applications that rely on ghostscript for routine document handling.

Techniques

Sample rules

Linux Ghostscript Exploitation

Description

The following analytic detects exploitation of Ghostscript causing command execution. This can be used by attackers to abuse file conversion services or embedded LibreOffice documents.

Detection logic


| tstats `security_content_summariesonly`
  count min(_time) as firstTime
        max(_time) as lastTime

from datamodel=Endpoint.Processes where

Processes.parent_process_path IN (
    "*/gs",
    "*/ghostscript"
)
Processes.process="sh -c*"

by Processes.process Processes.vendor_product Processes.user_id
   Processes.process_hash Processes.parent_process_name
   Processes.parent_process_exec Processes.action Processes.dest
   Processes.process_current_directory Processes.process_path
   Processes.process_integrity_level Processes.original_file_name
   Processes.parent_process Processes.parent_process_path
   Processes.parent_process_guid Processes.parent_process_id
   Processes.process_guid Processes.process_id Processes.user
   Processes.process_name


| `drop_dm_object_name(Processes)`

| `security_content_ctime(firstTime)`

| `security_content_ctime(lastTime)`

| `linux_ghostscript_exploitation_filter`