Outbound Network Connection Followed by Process File Deletion
Description
This rule detects a network connection attempt to an external IP address followed by a file deletion event where the file path is the same as the process executable. This behavior may indicate an attempt to cover tracks by deleting the file used to establish the connection, and may be used by attackers to hide their tracks upon successfully establishing a connection to a C2 server.
Query · eql
sequence by process.parent.entity_id with maxspan=10s
[network where event.type == "start" and event.action == "connection_attempted" and
process.executable like ("/tmp/*", "/var/tmp/*", "/dev/shm/*") and
not (
destination.ip == null or destination.ip == "0.0.0.0" or cidrmatch(
destination.ip, "10.0.0.0/8", "127.0.0.0/8", "169.254.0.0/16", "172.16.0.0/12", "192.0.0.0/24", "192.0.0.0/29",
"192.0.0.8/32", "192.0.0.9/32", "192.0.0.10/32", "192.0.0.170/32", "192.0.0.171/32", "192.0.2.0/24",
"192.31.196.0/24", "192.52.193.0/24", "192.168.0.0/16", "192.88.99.0/24", "224.0.0.0/4", "100.64.0.0/10",
"192.175.48.0/24","198.18.0.0/15", "198.51.100.0/24", "203.0.113.0/24", "240.0.0.0/4", "::1", "FE80::/10",
"FF00::/8"
) or
process.executable like (
"/tmp/regctl", "/tmp/token_handler", "/tmp/tmp.*/juliainstaller", "/tmp/tmp.*/rustup-init",
"/tmp/tmp.*/elan-init", "/var/tmp/tmp.*/rustup-init", "/tmp/SophosCentralInstall*/bin/telemetry",
"/tmp/bdconfigure.*/bdconfigure64", "/tmp/nanolayer*/nanolayer", "/tmp/tmp.*/pgp-file-protect",
"/tmp/tmp.*/rover", "/tmp/tmp.*/sq-ccm", "/tmp/trizen-fric/jfrog-cli/src/jfrog-cli-*/jf",
"/var/tmp/sdcss_Uninstalltelemetry/seticli", "/tmp/tmp.*/goreleaser", "/var/tmp/tmp.*/hab-x86_64-linux/hab",
"/tmp/buildroot-*/python/bin/python*", "/tmp/confluent"
)
)] as event0
[file where event.type == "deletion" and process.name == "rm" and startswith~(file.path, event0.process.executable)]