Linux sysinfo Syscall for System Information Discovery

Detects auditd-reported sysinfo syscalls on Linux that can indicate system fingerprinting or reconnaissance.

FreeReviewedSigma · Low · v3
Product
linux
Service
auditd
Author
Milad Cheraghi (SigmaHQ), DRL 1.1
Published
2025-05-30
Updated
2026-07-31

ATT&CK techniques

Discovery
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Persistence

  6. Priv Esc

  7. Defense Evasion

  8. Cred Access

  9. Lateral Movement

  10. Collection

  11. C2

  12. Exfiltration

  13. Impact

What it detects

This rule identifies Linux processes invoking the sysinfo system call, which returns a snapshot of system statistics such as uptime, load averages, memory usage, and process count. Such data is valuable to attackers performing reconnaissance or assessing whether a host is a viable target. It relies on auditd syscall telemetry that records SYSCALL type and the specific system call name.

Related detections9 linkedT1082 — drag to rearrange
Windows Process Execution of PCHunter (PCHunter64.exe or PCHunter32.exe)
Cisco AAA discovery via show/dir commands
Suspicious System Profiler Hardware Enumeration (via process_creation)
Antivirus Software Discovery via tasklist and findstr
Suspicious Hardware Inventory Discovery via WMIC Device Class Queries (via process_creation)
Suspicious macOS Hardware Identifier Reconnaissance via ioreg (via process_creation)
Suspicious Encoded PowerShell Host Reconnaissance via Get-ComputerInfo via ps_script
Suspicious Host Recon via ConvertFrom-Csv and ConvertTo-Json
Suspicious Java Process Spawning Reconnaissance Commands via Cleo MFT (via process_creation)
Linux sysinfo Syscall for System Information Discovery
Pivot detection · T1082 · 9 related

Changelog

v3
  1. v3
    Candidate ingested via manual entry.2026-07-31
  2. v2
    Candidate ingested via manual entry.2026-07-31
  3. v1
    No changelog recorded for this version.2026-07-30

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.