LoFP LoFP / some legitimate tooling and environment managers create or modify `sitecustomize.py`/`usercustomize.py` as part of normal setup. investigate the file contents and parent process to determine legitimacy.

Techniques

Sample rules

Python Site Hooks Creation During Package Installation

Description

The following analytic detects the creation of a Python site hook file (sitecustomize.py or usercustomize.py) within a site-packages/dist-packages directory in conjunction with a package installation process. Python’s site module loads these hooks from directories on sys.path before Python is executed. If an adversary manipulates or plants one of these files, they can hijack the Python environment and execute their payload with every Python invocation, achieving persistence on the victim endpoint. The VIPERTUNNEL backdoor was reported to abuse site hooks in order to import and trigger DLL execution. If confirmed malicious, this could result in arbitrary code execution every time Python is invoked on the compromised host.

Detection logic

`sysmon`
EventID IN (1,11)
(
    process="* install *"
    OR
    (
        action="created"
        file_path="*-packages\\*"
        file_path IN ("*sitecustomize.py", "*usercustomize.py")
    )
)


| stats count min(_time) as firstTime
              max(_time) as lastTime
              values(parent_process_id) as parent_process_id
              values(parent_process_path) as parent_process_path
              values(parent_process_name) as parent_process_name
              values(parent_process) as parent_process
              values(process_path) as process_path
              values(process_name) as process_name
              values(process) as process
              values(file_path) as file_path
              values(file_name) as file_name
              dc(EventID) as dc_event_id
              by dest source process_id


| search dc_event_id>1


| table firstTime lastTime
        parent_process_id parent_process_path parent_process_name parent_process
        process_id process_path process_name process
        file_path file_name
        dest source


| `security_content_ctime(firstTime)`

| `security_content_ctime(lastTime)`

| `python_site_hooks_creation_during_package_installation_filter`