Linux Remote System Discovery via arp or ping enumeration

Flags Linux arp or ping commands with LAN/loopback/link-local IP range arguments consistent with remote host discovery.

FreeUnreviewedSigmalowv1
title: Linux Remote System Discovery via arp or ping enumeration
id: b59b33fe-63af-4bb4-8b11-e53892d93354
status: test
description: This rule identifies Linux process executions of arp and ping commands with parameters commonly used to enumerate other hosts. Attackers often use network discovery to map reachable systems before scanning or exploitation. The detection relies on process creation telemetry, matching the executable path suffix (/arp or /ping) and specific command-line patterns for address ranges or arp invocation.
references:
  - https://github.com/redcanaryco/atomic-red-team/blob/f339e7da7d05f6057fdfcdd3742bfcf365fee2a9/atomics/T1018/T1018.md
  - https://github.com/SigmaHQ/sigma/blob/master/rules/linux/process_creation/proc_creation_lnx_remote_system_discovery.yml
author: Alejandro Ortuno, oscd.community, Huntrule Team
date: 2020-10-22
modified: 2021-11-27
tags:
  - attack.discovery
  - attack.t1018
logsource:
  category: process_creation
  product: linux
detection:
  selection_1:
    Image|endswith: /arp
    CommandLine|contains: -a
  selection_2:
    Image|endswith: /ping
    CommandLine|contains:
      - " 10."
      - " 192.168."
      - " 172.16."
      - " 172.17."
      - " 172.18."
      - " 172.19."
      - " 172.20."
      - " 172.21."
      - " 172.22."
      - " 172.23."
      - " 172.24."
      - " 172.25."
      - " 172.26."
      - " 172.27."
      - " 172.28."
      - " 172.29."
      - " 172.30."
      - " 172.31."
      - " 127."
      - " 169.254."
  condition: 1 of selection*
falsepositives:
  - Legitimate administration activities
level: low
license: DRL-1.1
related:
  - id: 11063ec2-de63-4153-935e-b1a8b9e616f1
    type: derived

What it detects

This rule identifies Linux process executions of arp and ping commands with parameters commonly used to enumerate other hosts. Attackers often use network discovery to map reachable systems before scanning or exploitation. The detection relies on process creation telemetry, matching the executable path suffix (/arp or /ping) and specific command-line patterns for address ranges or arp invocation.

Known false positives

  • Legitimate administration activities

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.