Skip to content

Snapattack Linux Conversions#4173

Open
RavenTait wants to merge 2 commits into
developfrom
snap_linux_ng
Open

Snapattack Linux Conversions#4173
RavenTait wants to merge 2 commits into
developfrom
snap_linux_ng

Conversation

@RavenTait

Copy link
Copy Markdown
Contributor

Details

This PR adds multiple new detections converted from Snap Attack. Below is a detailed summary of the changes introduced by the review.

New Analytics [24]

Multiple analytics (a total of 24) have been added in this PR covering a bunch of techniques.

  • Linux Bash History Access
  • Linux Bash Pseudo Device Reverse Shell
  • Linux Binary Executed from Shared Memory Directory
  • Linux EFI Bootloader File Deletion
  • Linux Ghostscript Exploitation
  • Linux MOTD Script Added
  • Linux Netcat Outbound Connection
  • Linux Persistence via System Generator
  • Linux Possible Bootloader Modifications
  • Linux Possible GSM Privilege Escalation
  • Linux Possible Nimbuspwn Privilege Escalation
  • Linux Possible Privilege Escalation via PYTHONPATH
  • Linux Possible System Binary Backdoor
  • Linux Root execution of id
  • Linux Suspicious Child Process of Postgresql
  • Linux Suspicious Docker Build
  • Linux Suspicious GCC Invocation Building Init Shared Object
  • Linux Suspicious Privileged Container
  • Linux Suspicious Redis Activity
  • Linux Suspicious Staging of Alternate System Files
  • Linux Suspicious Sudo Parameter
  • Linux Suspicious XDG Autostart
  • Linux UDEV Rule Created
  • Linux Usermod Root UID Set

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant