Cloud Credential Search Detected via Defend for Containers
Description
This rule detects the use of system search utilities like grep and find to search for AWS credentials inside a container. Unauthorized access to these sensitive files could lead to further compromise of the container environment or facilitate a container breakout to the underlying cloud environment.
Query · eql
process where host.os.type == "linux" and event.type == "start" and event.action == "exec" and (
process.name in ("grep", "egrep", "fgrep", "find", "locate", "mlocate", "cat", "sed", "awk") or
(
/* Account for tools that execute utilities as a subprocess, in this case the target utility name will appear as a process arg */
process.name in ("bash", "dash", "sh", "tcsh", "csh", "zsh", "ksh", "fish", "busybox") and
process.args in (
"grep", "/bin/grep", "/usr/bin/grep", "/usr/local/bin/grep",
"egrep", "/bin/egrep", "/usr/bin/egrep", "/usr/local/bin/egrep",
"fgrep", "/bin/fgrep", "/usr/bin/fgrep", "/usr/local/bin/fgrep",
"find", "/bin/find", "/usr/bin/find", "/usr/local/bin/find",
"locate", "/bin/locate", "/usr/bin/locate", "/usr/local/bin/locate",
"mlocate", "/bin/mlocate", "/usr/bin/mlocate", "/usr/local/bin/mlocate",
"cat", "/bin/cat", "/usr/bin/cat", "/usr/local/bin/cat",
"sed", "/bin/sed", "/usr/bin/sed", "/usr/local/bin/sed",
"awk", "/bin/awk", "/usr/bin/awk", "/usr/local/bin/awk"
) and
/* default exclusion list to not FP on default multi-process commands */
not process.args in (
"which", "/bin/which", "/usr/bin/which", "/usr/local/bin/which",
"man", "/bin/man", "/usr/bin/man", "/usr/local/bin/man",
"chmod", "/bin/chmod", "/usr/bin/chmod", "/usr/local/bin/chmod",
"chown", "/bin/chown", "/usr/bin/chown", "/usr/local/bin/chown"
)
)
)
and
process.args like~ (
/* AWS Credentials */
"*aws_access_key_id*", "*aws_secret_access_key*", "*aws_session_token*", "*accesskeyid*", "*secretaccesskey*",
"*access_key*", "*.aws/credentials*",
/* Azure Credentials */
"*AZURE_CLIENT_ID*", "*AZURE_TENANT_ID*", "*AZURE_CLIENT_SECRET*", "*AZURE_FEDERATED_TOKEN_FILE*",
"*IDENTITY_ENDPOINT*", "*IDENTITY_HEADER*", "*MSI_ENDPOINT*", "*MSI_SECRET*",
"*/.azure/*", "*/var/run/secrets/azure/*",
/* GCP Credentials */
"*/.config/gcloud/*", "*application_default_credentials.json*",
"*type: service_account*", "*client_email*", "*private_key_id*", "*private_key*",
"*/var/run/secrets/google/*", "*GOOGLE_APPLICATION_CREDENTIALS*"
) and container.id like "*"