Linux Persistence and Privilege Escalation Risk Behavior
Description
The following analytic identifies potential Linux persistence and privilege escalation activities. It leverages risk scores and event counts from various Linux-related data sources, focusing on tactics associated with persistence and privilege escalation. This activity is significant for a SOC because it highlights behaviors that could allow an attacker to maintain access or gain elevated privileges on a Linux system. If confirmed malicious, this activity could enable an attacker to execute code with higher privileges, persist in the environment, and potentially access sensitive information, posing a severe security risk.
Query · spl
| tstats `security_content_summariesonly` min(_time) as firstTime max(_time) as lastTime sum(All_Risk.calculated_risk_score) as risk_score, count(All_Risk.calculated_risk_score) as risk_event_count, values(All_Risk.annotations.mitre_attack.mitre_tactic_id) as annotations.mitre_attack.mitre_tactic_id, dc(All_Risk.annotations.mitre_attack.mitre_tactic_id) as mitre_tactic_id_count, values(All_Risk.annotations.mitre_attack.mitre_technique_id) as annotations.mitre_attack.mitre_technique_id, dc(All_Risk.annotations.mitre_attack.mitre_technique_id) as mitre_technique_id_count, values(All_Risk.tag) as tag, values(source) as source, dc(source) as source_count FROM datamodel=Risk.All_Risk
WHERE (
All_Risk.analyticstories IN ("Linux Privilege Escalation", "Linux Persistence Techniques")
OR
source = "*Linux*"
)
All_Risk.annotations.mitre_attack.mitre_tactic IN ("persistence", "privilege-escalation") All_Risk.risk_object_type="system"
BY All_Risk.risk_object All_Risk.risk_object_type All_Risk.annotations.mitre_attack.mitre_tactic
| `drop_dm_object_name(All_Risk)`
| `security_content_ctime(firstTime)`
| `security_content_ctime(lastTime)`
| where source_count >= 4
| `linux_persistence_and_privilege_escalation_risk_behavior_filter`
Rule dependencies
⚠ Higher-order rule. It fires on other rules' alerts, not on raw events, so it cannot fire on its own. Deploy the rules it depends on too.
Depends on
-
correlates · Splunk risk datamodel
Linux Persistence Techniques98 rules in this analytic story -
correlates · Splunk risk datamodel
Linux Privilege Escalation130 rules in this analytic story
Implementation guide
Ensure Linux anomaly and TTP analytics are enabled. TTP may be set to finding for point detections, anomaly should not be findings but risk generators. The correlation relies on more than x amount of distict detection names generated before generating a finding. Modify the value as needed. Default value is set to 4. This value may need to be increased based on activity in your environment.
Known false positives
- False positives will be present based on many factors. Tune the correlation as needed to reduce too many triggers.
Analyst notes
Known false positives: False positives will be present based on many factors. Tune the correlation as needed to reduce too many triggers.