LoFP LoFP / software developers or devops personnel may legitimately clone or download the ironpython repository from github for development purposes. filter as needed based on known developer hosts or users in your environment.

Techniques

Sample rules

Windows Process Accessing IronLanguages Repository On GitHub

Description

The following analytic identifies a process command line referencing the IronLanguages GitHub repository, which hosts .NET implementation of popular scripting engines. Adversaries have downloaded these .NET implementations to avoid getting detected by security controls while executing their payloads. This activity is uncommon in typical enterprise environments outside of software development contexts.

Detection logic


| tstats `security_content_summariesonly`
  count min(_time) as firstTime
        max(_time) as lastTime
FROM datamodel=Endpoint.Processes WHERE

Processes.process="*/ironlanguages/*"
Processes.process="*github.com*"

by Processes.action Processes.dest Processes.original_file_name
   Processes.parent_process Processes.parent_process_exec
   Processes.parent_process_guid Processes.parent_process_id
   Processes.parent_process_name Processes.parent_process_path
   Processes.process Processes.process_exec Processes.process_guid
   Processes.process_hash Processes.process_id
   Processes.process_integrity_level Processes.process_name
   Processes.process_path Processes.user Processes.user_id
   Processes.vendor_product


| `drop_dm_object_name(Processes)`

| `security_content_ctime(firstTime)`

| `security_content_ctime(lastTime)`

| `windows_process_accessing_ironlanguages_repository_on_github_filter`