Linux OS Architecture Discovery Using grep
Flags grep executions on Linux whose command line ends with known CPU/architecture identifiers.
- Product
- linux
- Category
- process_creation
- Author
- Joseliyo Sanchez, @Joseliyo_Jstnk (SigmaHQ), DRL 1.1
- Published
- 2023-06-02
- Updated
- 2026-07-31
ATT&CK techniques
DiscoveryRecon
Resource Dev
Initial Access
Execution
Persistence
Priv Esc
Defense Evasion
Cred Access
Discovery
Lateral Movement
Collection
C2
Exfiltration
Impact
What it detects
This rule flags Linux process executions where the binary name ends with '/grep' and the command line ends with architecture identifiers such as aarch64, arm, i386, i686, mips, or x86_64. Attackers use this kind of quick local system profiling to determine compatibility before payload selection or follow-on actions. It relies on process creation telemetry that includes the process image path and the full command line.
Reporting behind it
- blogs.jpcert.or.jphttps://blogs.jpcert.or.jp/en/2023/05/gobrat.html
- jstnk9.github.iohttps://jstnk9.github.io/jstnk9/research/GobRAT-Malware/
- virustotal.comhttps://www.virustotal.com/gui/file/60bcd645450e4c846238cf0e7226dc40c84c96eba99f6b2cffcd0ab4a391c8b3/detection
- virustotal.comhttps://www.virustotal.com/gui/file/3e44c807a25a56f4068b5b8186eee5002eed6f26d665a8b791c472ad154585d1/detection
- github.comhttps://github.com/SigmaHQ/sigma/blob/master/rules/linux/process_creation/proc_creation_lnx_grep_os_arch_discovery.yml
Changelog
v2- v2Candidate ingested via manual entry.2026-07-31
- v1No changelog recorded for this version.2026-07-30
Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.
title: Linux OS Architecture Discovery Using grep
id: aafd3b85-9b70-4d5b-8193-df9741e49584
status: test
description: This rule flags Linux process executions where the binary name ends with '/grep' and the command line ends with architecture identifiers such as aarch64, arm, i386, i686, mips, or x86_64. Attackers use this kind of quick local system profiling to determine compatibility before payload selection or follow-on actions. It relies on process creation telemetry that includes the process image path and the full command line.
references:
- https://blogs.jpcert.or.jp/en/2023/05/gobrat.html
- https://jstnk9.github.io/jstnk9/research/GobRAT-Malware/
- https://www.virustotal.com/gui/file/60bcd645450e4c846238cf0e7226dc40c84c96eba99f6b2cffcd0ab4a391c8b3/detection
- https://www.virustotal.com/gui/file/3e44c807a25a56f4068b5b8186eee5002eed6f26d665a8b791c472ad154585d1/detection
- https://github.com/SigmaHQ/sigma/blob/master/rules/linux/process_creation/proc_creation_lnx_grep_os_arch_discovery.yml
author: Joseliyo Sanchez, @Joseliyo_Jstnk, Huntrule Team
date: 2023-06-02
tags:
- attack.discovery
- attack.t1082
logsource:
category: process_creation
product: linux
detection:
selection_process:
Image|endswith: /grep
selection_architecture:
CommandLine|endswith:
- aarch64
- arm
- i386
- i686
- mips
- x86_64
condition: all of selection_*
falsepositives:
- Unknown
level: low
license: DRL-1.1
related:
- id: d27ab432-2199-483f-a297-03633c05bae6
type: derived