Linux OS Architecture Discovery Using grep for CPU/Arch Strings
Flags grep executions on Linux whose command line ends with known CPU/architecture identifiers.
FreeUnreviewedSigmalowv1
linux-os-architecture-discovery-using-grep-for-cpu-arch-strings-d27ab432
title: Linux OS Architecture Discovery Using grep for CPU/Arch Strings
id: aafd3b85-9b70-4d5b-8193-df9741e49584
status: test
description: This rule matches process creation events where the executable path ends with '/grep' and the command line ends with common architecture identifiers (aarch64, arm, i386, i686, mips, x86_64). Attackers may use grep to quickly gather host architecture details to tailor subsequent tooling, payloads, or configuration. Telemetry relies on Linux process creation data that includes the command image path and full command line arguments.
references:
- https://blogs.jpcert.or.jp/en/2023/05/gobrat.html
- https://jstnk9.github.io/jstnk9/research/GobRAT-Malware/
- https://www.virustotal.com/gui/file/60bcd645450e4c846238cf0e7226dc40c84c96eba99f6b2cffcd0ab4a391c8b3/detection
- https://www.virustotal.com/gui/file/3e44c807a25a56f4068b5b8186eee5002eed6f26d665a8b791c472ad154585d1/detection
- https://github.com/SigmaHQ/sigma/blob/master/rules/linux/process_creation/proc_creation_lnx_grep_os_arch_discovery.yml
author: Joseliyo Sanchez, @Joseliyo_Jstnk, Huntrule Team
date: 2023-06-02
tags:
- attack.discovery
- attack.t1082
logsource:
category: process_creation
product: linux
detection:
selection_process:
Image|endswith: /grep
selection_architecture:
CommandLine|endswith:
- aarch64
- arm
- i386
- i686
- mips
- x86_64
condition: all of selection_*
falsepositives:
- Unknown
level: low
license: DRL-1.1
related:
- id: d27ab432-2199-483f-a297-03633c05bae6
type: derived
What it detects
This rule matches process creation events where the executable path ends with '/grep' and the command line ends with common architecture identifiers (aarch64, arm, i386, i686, mips, x86_64). Attackers may use grep to quickly gather host architecture details to tailor subsequent tooling, payloads, or configuration. Telemetry relies on Linux process creation data that includes the command image path and full command line arguments.
Known false positives
- Unknown
Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.