Linux OS Architecture Discovery Using grep for CPU/Arch Strings

Flags grep executions on Linux whose command line ends with known CPU/architecture identifiers.

FreeUnreviewedSigmalowv1
title: Linux OS Architecture Discovery Using grep for CPU/Arch Strings
id: aafd3b85-9b70-4d5b-8193-df9741e49584
status: test
description: This rule matches process creation events where the executable path ends with '/grep' and the command line ends with common architecture identifiers (aarch64, arm, i386, i686, mips, x86_64). Attackers may use grep to quickly gather host architecture details to tailor subsequent tooling, payloads, or configuration. Telemetry relies on Linux process creation data that includes the command image path and full command line arguments.
references:
  - https://blogs.jpcert.or.jp/en/2023/05/gobrat.html
  - https://jstnk9.github.io/jstnk9/research/GobRAT-Malware/
  - https://www.virustotal.com/gui/file/60bcd645450e4c846238cf0e7226dc40c84c96eba99f6b2cffcd0ab4a391c8b3/detection
  - https://www.virustotal.com/gui/file/3e44c807a25a56f4068b5b8186eee5002eed6f26d665a8b791c472ad154585d1/detection
  - https://github.com/SigmaHQ/sigma/blob/master/rules/linux/process_creation/proc_creation_lnx_grep_os_arch_discovery.yml
author: Joseliyo Sanchez, @Joseliyo_Jstnk, Huntrule Team
date: 2023-06-02
tags:
  - attack.discovery
  - attack.t1082
logsource:
  category: process_creation
  product: linux
detection:
  selection_process:
    Image|endswith: /grep
  selection_architecture:
    CommandLine|endswith:
      - aarch64
      - arm
      - i386
      - i686
      - mips
      - x86_64
  condition: all of selection_*
falsepositives:
  - Unknown
level: low
license: DRL-1.1
related:
  - id: d27ab432-2199-483f-a297-03633c05bae6
    type: derived

What it detects

This rule matches process creation events where the executable path ends with '/grep' and the command line ends with common architecture identifiers (aarch64, arm, i386, i686, mips, x86_64). Attackers may use grep to quickly gather host architecture details to tailor subsequent tooling, payloads, or configuration. Telemetry relies on Linux process creation data that includes the command image path and full command line arguments.

Known false positives

  • Unknown

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.