Python Script Execution via Shell and Remote Network Connection
Description
This rule looks for the specific behavior exhibited when the Python sample utilizes the subprocess.Popen method, setting the shell variable equal to True, in order to execute an embedded Python script that connects to a remote server in order to retrieve and execute a command which gets written to a temporary file and executed.
Query · eql
sequence by process.parent.entity_id with maxspan=3s
[process where event.type == "start" and event.action == "exec" and process.parent.name like~ "python*" and
process.name in ("sh", "zsh", "bash") and process.args == "-c" and process.args like~ "python*" and
process.args like~ "*.py" and process.args_count == 3 and
not process.command_line like~ "* pip*"]
[network where event.type == "start" and
not cidrmatch(destination.ip,
"240.0.0.0/4", "233.252.0.0/24", "224.0.0.0/4", "198.19.0.0/16", "192.18.0.0/15",
"192.0.0.0/24", "10.0.0.0/8", "127.0.0.0/8", "169.254.0.0/16", "172.16.0.0/12",
"192.0.2.0/24", "192.31.196.0/24", "192.52.193.0/24", "192.168.0.0/16", "192.88.99.0/24",
"100.64.0.0/10", "192.175.48.0/24", "198.18.0.0/15", "198.51.100.0/24", "203.0.113.0/24",
"::1", "FE80::/10", "FF00::/8")]