Linux Powershell Egress Network Connection
Description
Detects when Powershell (pwsh) on Linux makes an outbound network connection attempt. Powershell usage on Linux is rare, and leveraging Powershell to connect out to the internet may indicate malicious behavior.
Query · eql
sequence by process.entity_id with maxspan=5s
[process where event.type == "start" and event.action == "exec" and process.parent.name == "pwsh" and not (
process.name in ("kubectl", "helm", "pwsh", "yum", "dnf", "dotnet", "ansible-lint") or
process.executable like (
"/run/containerd/*python3", "/jenkins-data/docker/*python3", "/tmp/Download-References/DepotDownloader/DepotDownloader",
"/home/*/.local/bin/az", "/usr/libexec/platform-python*"
) or
process.parent.executable like ("/jenkins-data/docker*", "/var/run/docker/*", "/run/containerd/*") or
process.command_line == "/usr/bin/gh auth status" or
(process.name like "python*" and process.args == "azure.cli") or
process.working_directory like "/opt/azurevstsagent/agent*" or
process.args == "/bin/dnf" or
process.args like "/home/*/.local/bin/az"
)
]
[network where event.type == "start" and event.action == "connection_attempted" and not (
destination.ip == null or
destination.ip == "0.0.0.0" or
cidrmatch(
destination.ip, "10.0.0.0/8", "127.0.0.0/8", "169.254.0.0/16", "172.16.0.0/12", "192.0.0.0/24", "192.0.0.0/29",
"192.0.0.8/32", "192.0.0.9/32", "192.0.0.10/32", "192.0.0.170/32", "192.0.0.171/32", "192.0.2.0/24",
"192.31.196.0/24", "192.52.193.0/24", "192.168.0.0/16", "192.88.99.0/24", "224.0.0.0/4", "100.64.0.0/10",
"192.175.48.0/24","198.18.0.0/15", "198.51.100.0/24", "203.0.113.0/24", "240.0.0.0/4", "::1", "FE80::/10",
"FF00::/8"
) or
process.name == "ssh"
)
]