Linux Auditd: Process Executions of Telnet/Nmap/Netcat for Network Service Scanning
Alerts when telnet/nmap/netcat-style binaries are executed on Linux via auditd, consistent with service discovery scanning.
FreeUnreviewedSigmalowv1
linux-auditd-process-executions-of-telnet-nmap-netcat-for-network-service-scanni-3761e026
title: "Linux Auditd: Process Executions of Telnet/Nmap/Netcat for Network Service Scanning"
id: d4d3414e-f718-4e8e-9419-ceaf7672f310
related:
- id: 3e102cd9-a70d-4a7a-9508-403963092f31
type: derived
- id: 3761e026-f259-44e6-8826-719ed8079408
type: derived
status: test
description: This rule flags auditd syscall events where the executing binary path ends with telnet, nmap, netcat, nc, ncat, or nc.openbsd. Such tools are commonly used to enumerate local or remote services, which can indicate reconnaissance prior to exploitation. The detection relies on auditd telemetry capturing syscall type events and the process executable name/path ending patterns.
references:
- https://github.com/redcanaryco/atomic-red-team/blob/f339e7da7d05f6057fdfcdd3742bfcf365fee2a9/atomics/T1046/T1046.md
- https://github.com/SigmaHQ/sigma/blob/master/rules/linux/auditd/syscall/lnx_auditd_network_service_scanning.yml
author: Alejandro Ortuno, oscd.community, Huntrule Team
date: 2020-10-21
modified: 2023-09-26
tags:
- attack.discovery
- attack.t1046
logsource:
product: linux
service: auditd
definition: Configure these rules https://github.com/Neo23x0/auditd/blob/e181243a7c708e9d579557d6f80e0ed3d3483b89/audit.rules#L182-L183
detection:
selection:
type: SYSCALL
exe|endswith:
- /telnet
- /nmap
- /netcat
- /nc
- /ncat
- /nc.openbsd
key: network_connect_4
condition: selection
falsepositives:
- Legitimate administration activities
level: low
license: DRL-1.1
What it detects
This rule flags auditd syscall events where the executing binary path ends with telnet, nmap, netcat, nc, ncat, or nc.openbsd. Such tools are commonly used to enumerate local or remote services, which can indicate reconnaissance prior to exploitation. The detection relies on auditd telemetry capturing syscall type events and the process executable name/path ending patterns.
Known false positives
- Legitimate administration activities
Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.