Linux process execution match for known hacktool and scanning binaries

Alerts on Linux process executions of known hacktool, scanner, web enumeration, and exploit utility binaries by image name.

FreeUnreviewedSigmahighv1
title: Linux process execution match for known hacktool and scanning binaries
id: 1d763ef6-a21b-4c6a-9a48-576f6a26a573
status: test
description: This rule flags Linux process creation events where the executable image name matches a curated set of known hacktools, scanners, and enumeration utilities. Such tools are commonly used to enumerate systems, test services for vulnerabilities, and facilitate follow-on exploitation. The detection relies on process creation telemetry and pattern matching against the process image path or filename endings/contents.
references:
  - https://github.com/Gui774ume/ebpfkit
  - https://github.com/pathtofile/bad-bpf
  - https://github.com/carlospolop/PEASS-ng
  - https://github.com/t3l3machus/hoaxshell
  - https://github.com/t3l3machus/Villain
  - https://github.com/HavocFramework/Havoc
  - https://github.com/1N3/Sn1per
  - https://github.com/Ne0nd0g/merlin
  - https://github.com/Pennyw0rth/NetExec/
  - https://github.com/SigmaHQ/sigma/blob/master/rules/linux/process_creation/proc_creation_lnx_susp_hktl_execution.yml
author: Nasreddine Bencherchali (Nextron Systems), Georg Lauenstein (sure[secure]), Huntrule Team
date: 2023-01-03
modified: 2024-09-19
tags:
  - attack.execution
  - attack.resource-development
  - attack.t1587
logsource:
  product: linux
  category: process_creation
detection:
  selection_c2_frameworks:
    Image|endswith:
      - /crackmapexec
      - /havoc
      - /merlin-agent
      - /merlinServer-Linux-x64
      - /msfconsole
      - /msfvenom
      - /ps-empire server
      - /ps-empire
      - /sliver-client
      - /sliver-server
      - /Villain.py
  selection_c2_framework_cobaltstrike:
    Image|contains:
      - /cobaltstrike
      - /teamserver
  selection_scanners:
    Image|endswith:
      - /autorecon
      - /httpx
      - /legion
      - /naabu
      - /netdiscover
      - /nuclei
      - /recon-ng
  selection_scanners_sniper:
    Image|contains: /sniper
  selection_web_enum:
    Image|endswith:
      - /dirb
      - /dirbuster
      - /eyewitness
      - /feroxbuster
      - /ffuf
      - /gobuster
      - /wfuzz
      - /whatweb
  selection_web_vuln:
    Image|endswith:
      - /joomscan
      - /nikto
      - /wpscan
  selection_exploit_tools:
    Image|endswith:
      - /aircrack-ng
      - /bloodhound-python
      - /bpfdos
      - /ebpfki
      - /evil-winrm
      - /hashcat
      - /hoaxshell.py
      - /hydra
      - /john
      - /ncrack
      - /nxc-ubuntu-latest
      - /pidhide
      - /pspy32
      - /pspy32s
      - /pspy64
      - /pspy64s
      - /setoolkit
      - /sqlmap
      - /writeblocker
  selection_linpeas:
    Image|contains: /linpeas
  condition: 1 of selection_*
falsepositives:
  - Unlikely
level: high
license: DRL-1.1
related:
  - id: a015e032-146d-4717-8944-7a1884122111
    type: derived

What it detects

This rule flags Linux process creation events where the executable image name matches a curated set of known hacktools, scanners, and enumeration utilities. Such tools are commonly used to enumerate systems, test services for vulnerabilities, and facilitate follow-on exploitation. The detection relies on process creation telemetry and pattern matching against the process image path or filename endings/contents.

Known false positives

  • Unlikely

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.