elastic / detection-rules

https://www.elastic.co/guide/en/security/current/detection-engine-overview.html
Other
1.91k stars 492 forks source link

[New Rules] Yum Plugin Creation / Discovery #3820

Closed Aegrah closed 3 months ago

Aegrah commented 3 months ago

This PR adds two new rules:

  1. Yum Package Manager Plugin File Creation
  2. Yum Plugin Status Discovery

Yum Package Manager Plugin File Creation

Detects plugin creations in Yum plugin directories, which can be abused for persistence. Only TPs in my stack, 0 FPs in telemetry last 90d.

image

Yum Plugin Status Discovery

Detects the usage of grep to check whether plugins are enabled in the yum configuration. Only TPs in my stack, running Metasploit modules / my own tool & 0 FPs in telemetry last 90d.

image