Shared Object Created or Changed by Previously Unknown Process

This rule monitors the creation of shared object files by previously unknown processes. The creation of a shared object file involves compiling code into a dynamically linked library that can be loaded by other programs at runtime. While this process is typically used for legitimate purposes, malicious actors can leverage shared object files to execute unauthorized code, inject malicious functionality into legitimate processes, or bypass security controls. This allows malware to persist on the system, evade detection, and potentially compromise the integrity and confidentiality of the affected system and its data.

Elastic rule (View on GitHub)

 1[metadata]
 2creation_date = "2023/06/09"
 3integration = ["endpoint"]
 4maturity = "production"
 5min_stack_comments = "New fields added: required_fields, related_integrations, setup, New Term"
 6min_stack_version = "8.6.0"
 7updated_date = "2023/07/31"
 8
 9[rule]
10author = ["Elastic"]
11description = """
12This rule monitors the creation of shared object files by previously unknown processes. The creation of a shared object
13file involves compiling code into a dynamically linked library that can be loaded by other programs at runtime. While
14this process is typically used for legitimate purposes, malicious actors can leverage shared object files to execute
15unauthorized code, inject malicious functionality into legitimate processes, or bypass security controls. This allows
16malware to persist on the system, evade detection, and potentially compromise the integrity and confidentiality of the
17affected system and its data.
18"""
19from = "now-9m"
20index = ["logs-endpoint.events.*", "endgame-*"]
21language = "kuery"
22license = "Elastic License v2"
23name = "Shared Object Created or Changed by Previously Unknown Process"
24references = ["https://threatpost.com/sneaky-malware-backdoors-linux/180158/"]
25risk_score = 47
26rule_id = "aebaa51f-2a91-4f6a-850b-b601db2293f4"
27severity = "medium"
28tags = ["Domain: Endpoint", "OS: Linux", "Use Case: Threat Detection", "Tactic: Persistence", "Data Source: Elastic Endgame", "Data Source: Elastic Defend"]
29timestamp_override = "event.ingested"
30type = "new_terms"
31
32query = '''
33host.os.type:linux and event.action:(creation or file_create_event or file_rename_event or rename) and 
34file.path:(/dev/shm/* or /usr/lib/*) and file.extension:so and 
35process.name: ( * and not ("5" or "dockerd" or "dpkg" or "rpm" or "snapd" or "exe" or "yum" or "vmis-launcher"))
36'''
37
38
39[[rule.threat]]
40framework = "MITRE ATT&CK"
41[[rule.threat.technique]]
42id = "T1574"
43name = "Hijack Execution Flow"
44reference = "https://attack.mitre.org/techniques/T1574/"
45[[rule.threat.technique.subtechnique]]
46id = "T1574.006"
47name = "Dynamic Linker Hijacking"
48reference = "https://attack.mitre.org/techniques/T1574/006/"
49
50
51
52[rule.threat.tactic]
53id = "TA0003"
54name = "Persistence"
55reference = "https://attack.mitre.org/tactics/TA0003/"
56
57[rule.new_terms]
58field = "new_terms_fields"
59value = ["file.path", "process.name"]
60[[rule.new_terms.history_window_start]]
61field = "history_window_start"
62value = "now-7d"

References

Related rules

to-top