Python Script Execution via Shell and Remote Network Connection


Description

This rule looks for the specific behavior exhibited when the Python sample utilizes the subprocess.Popen method, setting the shell variable equal to True, in order to execute an embedded Python script that connects to a remote server in order to retrieve and execute a command which gets written to a temporary file and executed.

Query · eql

sequence by process.parent.entity_id with maxspan=3s
[process where event.type == "start" and event.action == "exec" and process.parent.name like~ "python*" and 
  process.name in ("sh", "zsh", "bash") and process.args == "-c" and process.args like~ "python*" and 
  process.args like~ "*.py" and process.args_count == 3 and 
  not process.command_line like~ "* pip*"]
[network where event.type == "start" and
   not cidrmatch(destination.ip, 
       "240.0.0.0/4", "233.252.0.0/24", "224.0.0.0/4", "198.19.0.0/16", "192.18.0.0/15", 
       "192.0.0.0/24", "10.0.0.0/8", "127.0.0.0/8", "169.254.0.0/16", "172.16.0.0/12", 
       "192.0.2.0/24", "192.31.196.0/24", "192.52.193.0/24", "192.168.0.0/16", "192.88.99.0/24", 
       "100.64.0.0/10", "192.175.48.0/24", "198.18.0.0/15", "198.51.100.0/24", "203.0.113.0/24",
       "::1", "FE80::/10", "FF00::/8")]
Raw source Python Script Execution via Shell and Remote Network Connection · Elastic TOML
Esc
Published by elastic/protections-artifacts ↗, licensed under Elastic License 2.0 ↗. Reproduced here unmodified.
[rule]
description = """
This rule looks for the specific behavior exhibited when the Python sample utilizes the subprocess.Popen method, setting
the shell variable equal to True, in order to execute an embedded Python script that connects to a remote server in
order to retrieve and execute a command which gets written to a temporary file and executed.
"""
id = "f5c2b536-d7a7-4724-a149-a7e717e40429"
license = "Elastic License v2"
name = "Python Script Execution via Shell and Remote Network Connection"
os_list = ["macos"]
reference = [
    "https://www.reversinglabs.com/blog/fake-recruiter-coding-tests-target-devs-with-malicious-python-packages",
]
version = "1.0.8"

query = '''
sequence by process.parent.entity_id with maxspan=3s
[process where event.type == "start" and event.action == "exec" and process.parent.name like~ "python*" and 
  process.name in ("sh", "zsh", "bash") and process.args == "-c" and process.args like~ "python*" and 
  process.args like~ "*.py" and process.args_count == 3 and 
  not process.command_line like~ "* pip*"]
[network where event.type == "start" and
   not cidrmatch(destination.ip, 
       "240.0.0.0/4", "233.252.0.0/24", "224.0.0.0/4", "198.19.0.0/16", "192.18.0.0/15", 
       "192.0.0.0/24", "10.0.0.0/8", "127.0.0.0/8", "169.254.0.0/16", "172.16.0.0/12", 
       "192.0.2.0/24", "192.31.196.0/24", "192.52.193.0/24", "192.168.0.0/16", "192.88.99.0/24", 
       "100.64.0.0/10", "192.175.48.0/24", "198.18.0.0/15", "198.51.100.0/24", "203.0.113.0/24",
       "::1", "FE80::/10", "FF00::/8")]
'''

min_endpoint_version = "8.16.0"
optional_actions = []
[[actions]]
action = "kill_process"
field = "process.entity_id"
state = 0

[[actions]]
action = "kill_process"
field = "process.parent.entity_id"
state = 0

[[threat]]
framework = "MITRE ATT&CK"
[[threat.technique]]
id = "T1059"
name = "Command and Scripting Interpreter"
reference = "https://attack.mitre.org/techniques/T1059/"
[[threat.technique.subtechnique]]
id = "T1059.006"
name = "Python"
reference = "https://attack.mitre.org/techniques/T1059/006/"



[threat.tactic]
id = "TA0002"
name = "Execution"
reference = "https://attack.mitre.org/tactics/TA0002/"
[[threat]]
framework = "MITRE ATT&CK"
[[threat.technique]]
id = "T1105"
name = "Ingress Tool Transfer"
reference = "https://attack.mitre.org/techniques/T1105/"


[threat.tactic]
id = "TA0011"
name = "Command and Control"
reference = "https://attack.mitre.org/tactics/TA0011/"

[internal]
min_endpoint_version = "8.16.0"

Detection rules belong to the projects that publish them and remain under their own licenses. This site indexes and links to them; it claims no rights in them.