Linux Remote System Discovery via arp or ping enumeration
Flags Linux arp or ping commands with LAN/loopback/link-local IP range arguments consistent with remote host discovery.
FreeUnreviewedSigmalowv1
linux-remote-system-discovery-via-arp-or-ping-enumeration-11063ec2
title: Linux Remote System Discovery via arp or ping enumeration
id: b59b33fe-63af-4bb4-8b11-e53892d93354
status: test
description: This rule identifies Linux process executions of arp and ping commands with parameters commonly used to enumerate other hosts. Attackers often use network discovery to map reachable systems before scanning or exploitation. The detection relies on process creation telemetry, matching the executable path suffix (/arp or /ping) and specific command-line patterns for address ranges or arp invocation.
references:
- https://github.com/redcanaryco/atomic-red-team/blob/f339e7da7d05f6057fdfcdd3742bfcf365fee2a9/atomics/T1018/T1018.md
- https://github.com/SigmaHQ/sigma/blob/master/rules/linux/process_creation/proc_creation_lnx_remote_system_discovery.yml
author: Alejandro Ortuno, oscd.community, Huntrule Team
date: 2020-10-22
modified: 2021-11-27
tags:
- attack.discovery
- attack.t1018
logsource:
category: process_creation
product: linux
detection:
selection_1:
Image|endswith: /arp
CommandLine|contains: -a
selection_2:
Image|endswith: /ping
CommandLine|contains:
- " 10."
- " 192.168."
- " 172.16."
- " 172.17."
- " 172.18."
- " 172.19."
- " 172.20."
- " 172.21."
- " 172.22."
- " 172.23."
- " 172.24."
- " 172.25."
- " 172.26."
- " 172.27."
- " 172.28."
- " 172.29."
- " 172.30."
- " 172.31."
- " 127."
- " 169.254."
condition: 1 of selection*
falsepositives:
- Legitimate administration activities
level: low
license: DRL-1.1
related:
- id: 11063ec2-de63-4153-935e-b1a8b9e616f1
type: derived
What it detects
This rule identifies Linux process executions of arp and ping commands with parameters commonly used to enumerate other hosts. Attackers often use network discovery to map reachable systems before scanning or exploitation. The detection relies on process creation telemetry, matching the executable path suffix (/arp or /ping) and specific command-line patterns for address ranges or arp invocation.
Known false positives
- Legitimate administration activities
Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.