Linux coverage

426 of 1,429 Linux detection rules across 5 vendors map to a specific auditd record type or Sysmon-for-Linux event; the remaining 1,003 are grouped by MITRE technique.

Attributed to a catalog event

426 rules that resolve to a specific Linux Auditd record type or Sysmon-for-Linux event, mapped to that catalog event.

Linux Auditd (kernel audit records)

ADD_USER 2 rules
BPRM_FCAPS 1 rule
CRED_ACQ 1 rule
CWD 7 rules
DAEMON_ABORT 1 rule
DAEMON_END 1 rule
DAEMON_START 1 rule
EXECVE 58 rules
PATH 20 rules
PROCTITLE 21 rules
SERVICE_STOP 7 rules
SYSCALL 27 rules
TTY 1 rule
USER_ACCT 1 rule
USER_AUTH 2 rules
USER_CMD 2 rules
USER_END 2 rules
USER_LOGIN 1 rule
USER_START 3 rules
USER_TTY 1 rule

Sysmon for Linux

File created 47 rules
Network connection 6 rules
Process Create 246 rules

Not attributed to a catalog event

1,003 rules that target Linux but resolve to no specific catalog event (generic process / syslog fields, or a vendor the converter does not event-fold), grouped by the MITRE technique they detect.

Reconnaissance

(no specific technique) 1 rule
T1589 Gather Victim Identity Information 1 rule
T1595 Active Scanning 2 rules
T1595.002 Active Scanning: Vulnerability Scanning 1 rule
T1595.003 Active Scanning: Wordlist Scanning 1 rule

Resource Development

T1587.001 Develop Capabilities: Malware 1 rule
T1588.001 Obtain Capabilities: Malware 2 rules

Initial Access

T1078 Valid Accounts 18 rules
T1078.003 Valid Accounts: Local Accounts 2 rules
T1133 External Remote Services 7 rules
T1189 Drive-by Compromise 9 rules
T1190 Exploit Public-Facing Application 33 rules
T1195 Supply Chain Compromise 2 rules
T1195.001 Supply Chain Compromise: Compromise Software Dependencies and Development Tools 4 rules
T1195.002 Supply Chain Compromise: Compromise Software Supply Chain 6 rules
T1200 Hardware Additions 1 rule
T1566 Phishing 5 rules
T1566.002 Phishing: Spearphishing Link 1 rule

Execution

(no specific technique) 1 rule
T1053 Scheduled Task/Job 2 rules
T1053.002 Scheduled Task/Job: At 3 rules
T1053.003 Scheduled Task/Job: Cron 9 rules
T1053.006 Scheduled Task/Job: Systemd Timers 2 rules
T1053.007 Scheduled Task/Job: Container Orchestration Job 1 rule
T1059 Command and Scripting Interpreter 23 rules
T1059.001 Command and Scripting Interpreter: PowerShell 9 rules
T1059.002 Command and Scripting Interpreter: AppleScript 1 rule
T1059.003 Command and Scripting Interpreter: Windows Command Shell 3 rules
T1059.004 Command and Scripting Interpreter: Unix Shell 213 rules
T1059.006 Command and Scripting Interpreter: Python 33 rules
T1059.007 Command and Scripting Interpreter: JavaScript 9 rules
T1059.011 Command and Scripting Interpreter: Lua 10 rules
T1072 Software Deployment Tools 1 rule
T1106 Native API 20 rules
T1129 Shared Modules 2 rules
T1203 Exploitation for Client Execution 15 rules
T1204 User Execution 2 rules
T1204.001 User Execution: Malicious Link 3 rules
T1204.002 User Execution: Malicious File 19 rules
T1204.004 User Execution: Malicious Copy and Paste 2 rules
T1559 Inter-Process Communication 2 rules
T1569.002 System Services: Service Execution 2 rules
T1574 Hijack Execution Flow 25 rules
T1574.006 Hijack Execution Flow: Dynamic Linker Hijacking 7 rules
T1574.007 Hijack Execution Flow: Path Interception by PATH Environment Variable 2 rules
T1609 Container Administration Command 14 rules
T1610 Deploy Container 6 rules
T1651 Cloud Administration Command 1 rule

Persistence

(no specific technique) 3 rules
T1037 Boot or Logon Initialization Scripts 15 rules
T1037.004 Boot or Logon Initialization Scripts: RC Scripts 9 rules
T1053 Scheduled Task/Job 2 rules
T1053.002 Scheduled Task/Job: At 4 rules
T1053.003 Scheduled Task/Job: Cron 13 rules
T1053.006 Scheduled Task/Job: Systemd Timers 2 rules
T1053.007 Scheduled Task/Job: Container Orchestration Job 2 rules
T1078 Valid Accounts 4 rules
T1078.003 Valid Accounts: Local Accounts 2 rules
T1098 Account Manipulation 9 rules
T1098.004 Account Manipulation: SSH Authorized Keys 7 rules
T1098.007 Account Manipulation: Additional Local or Domain Groups 3 rules
T1133 External Remote Services 3 rules
T1136 Create Account 1 rule
T1136.001 Create Account: Local Account 10 rules
T1205.001 Traffic Signaling: Port Knocking 1 rule
T1505.001 Server Software Component: SQL Stored Procedures 1 rule
T1505.003 Server Software Component: Web Shell 20 rules
T1542 Pre-OS Boot 6 rules
T1542.003 Pre-OS Boot: Bootkit 1 rule
T1543 Create or Modify System Process 38 rules
T1543.002 Create or Modify System Process: Systemd Service 15 rules
T1543.003 Create or Modify System Process: Windows Service 1 rule
T1543.004 Create or Modify System Process: Launch Daemon 1 rule
T1543.005 Create or Modify System Process: Container Service 2 rules
T1546 Event Triggered Execution 11 rules
T1546.004 Event Triggered Execution: Unix Shell Configuration Modification 11 rules
T1546.016 Event Triggered Execution: Installer Packages 11 rules
T1546.017 Event Triggered Execution: Udev Rules 3 rules
T1546.018 Event Triggered Execution: Python Startup Hooks 2 rules
T1547 Boot or Logon Autostart Execution 1 rule
T1547.006 Boot or Logon Autostart Execution: Kernel Modules and Extensions 19 rules
T1547.013 Boot or Logon Autostart Execution: XDG Autostart Entries 5 rules
T1554 Compromise Host Software Binary 8 rules
T1556 Modify Authentication Process 10 rules
T1556.003 Modify Authentication Process: Pluggable Authentication Modules 5 rules

Privilege Escalation

(no specific technique) 2 rules
T1037 Boot or Logon Initialization Scripts 6 rules
T1037.004 Boot or Logon Initialization Scripts: RC Scripts 7 rules
T1053 Scheduled Task/Job 2 rules
T1053.002 Scheduled Task/Job: At 4 rules
T1053.003 Scheduled Task/Job: Cron 10 rules
T1053.006 Scheduled Task/Job: Systemd Timers 1 rule
T1053.007 Scheduled Task/Job: Container Orchestration Job 2 rules
T1055 Process Injection 1 rule
T1055.008 Process Injection: Ptrace System Calls 3 rules
T1068 Exploitation for Privilege Escalation 65 rules
T1078 Valid Accounts 3 rules
T1078.003 Valid Accounts: Local Accounts 2 rules
T1098 Account Manipulation 7 rules
T1098.004 Account Manipulation: SSH Authorized Keys 4 rules
T1098.007 Account Manipulation: Additional Local or Domain Groups 2 rules
T1543 Create or Modify System Process 12 rules
T1543.002 Create or Modify System Process: Systemd Service 12 rules
T1543.004 Create or Modify System Process: Launch Daemon 1 rule
T1543.005 Create or Modify System Process: Container Service 2 rules
T1546 Event Triggered Execution 4 rules
T1546.004 Event Triggered Execution: Unix Shell Configuration Modification 7 rules
T1546.016 Event Triggered Execution: Installer Packages 4 rules
T1546.017 Event Triggered Execution: Udev Rules 2 rules
T1546.018 Event Triggered Execution: Python Startup Hooks 2 rules
T1547.006 Boot or Logon Autostart Execution: Kernel Modules and Extensions 9 rules
T1547.013 Boot or Logon Autostart Execution: XDG Autostart Entries 2 rules
T1548 Abuse Elevation Control Mechanism 9 rules
T1548.001 Abuse Elevation Control Mechanism: Setuid and Setgid 32 rules
T1548.002 Abuse Elevation Control Mechanism: Bypass User Account Control 1 rule
T1548.003 Abuse Elevation Control Mechanism: Sudo and Sudo Caching 20 rules
T1611 Escape to Host 27 rules

Stealth

(no specific technique) 4 rules
T1006 Direct Volume Access 3 rules
T1014 Rootkit 27 rules
T1027 Obfuscated Files or Information 15 rules
T1027.004 Obfuscated Files or Information: Compile After Delivery 2 rules
T1027.010 Obfuscated Files or Information: Command Obfuscation 4 rules
T1027.013 Obfuscated Files or Information: Encrypted/Encoded File 1 rule
T1027.015 Obfuscated Files or Information: Compression 1 rule
T1036 Masquerading 4 rules
T1036.003 Masquerading: Rename Legitimate Utilities 3 rules
T1036.004 Masquerading: Masquerade Task or Service 3 rules
T1036.005 Masquerading: Match Legitimate Resource Name or Location 9 rules
T1036.006 Masquerading: Space after Filename 1 rule
T1036.008 Masquerading: Masquerade File Type 1 rule
T1036.009 Masquerading: Break Process Trees 3 rules
T1055 Process Injection 2 rules
T1055.008 Process Injection: Ptrace System Calls 3 rules
T1055.009 Process Injection: Proc Memory 13 rules
T1070 Indicator Removal 18 rules
T1070.003 Indicator Removal: Clear Command History 5 rules
T1070.004 Indicator Removal: File Deletion 13 rules
T1070.006 Indicator Removal: Timestomp 2 rules
T1078 Valid Accounts 2 rules
T1078.003 Valid Accounts: Local Accounts 4 rules
T1127 Trusted Developer Utilities Proxy Execution 1 rule
T1140 Deobfuscate/Decode Files or Information 23 rules
T1202 Indirect Command Execution 2 rules
T1211 Exploitation for Stealth 3 rules
T1218 System Binary Proxy Execution 20 rules
T1218.011 System Binary Proxy Execution: Rundll32 1 rule
T1497.001 Virtualization/Sandbox Evasion: System Checks 2 rules
T1542 Pre-OS Boot 5 rules
T1542.003 Pre-OS Boot: Bootkit 1 rule
T1564 Hide Artifacts 19 rules
T1564.001 Hide Artifacts: Hidden Files and Directories 14 rules
T1564.002 Hide Artifacts: Hidden Users 3 rules
T1574 Hijack Execution Flow 34 rules
T1574.006 Hijack Execution Flow: Dynamic Linker Hijacking 17 rules
T1574.007 Hijack Execution Flow: Path Interception by PATH Environment Variable 3 rules
T1574.013 Hijack Execution Flow: KernelCallbackTable 2 rules
T1620 Reflective Code Loading 23 rules

Defense Impairment

T1222.002 File and Directory Permissions Modification: Linux and Mac Permissions 13 rules
T1553 Subvert Trust Controls 2 rules
T1553.004 Subvert Trust Controls: Install Root Certificate 1 rule
T1599 Network Boundary Bridging 1 rule
T1601.001 Modify System Image: Patch System Image 1 rule
T1685 Disable or Modify Tools 47 rules
T1685.001 Disable or Modify Tools: Disable or Modify Windows Event Log 1 rule
T1685.006 Disable or Modify Tools: Clear Linux or Mac System Logs 8 rules
T1686 Disable or Modify System Firewall 2 rules

Credential Access

T1003 OS Credential Dumping 3 rules
T1003.007 OS Credential Dumping: Proc Filesystem 9 rules
T1003.008 OS Credential Dumping: /etc/passwd and /etc/shadow 11 rules
T1040 Network Sniffing 2 rules
T1056 Input Capture 2 rules
T1056.002 Input Capture: GUI Input Capture 2 rules
T1110 Brute Force 10 rules
T1110.001 Brute Force: Password Guessing 6 rules
T1110.002 Brute Force: Password Cracking 1 rule
T1110.003 Brute Force: Password Spraying 4 rules
T1212 Exploitation for Credential Access 6 rules
T1528 Steal Application Access Token 5 rules
T1539 Steal Web Session Cookie 1 rule
T1552 Unsecured Credentials 2 rules
T1552.001 Unsecured Credentials: Credentials In Files 22 rules
T1552.004 Unsecured Credentials: Private Keys 4 rules
T1552.005 Unsecured Credentials: Cloud Instance Metadata API 4 rules
T1552.007 Unsecured Credentials: Container API 1 rule
T1555 Credentials from Password Stores 4 rules
T1556 Modify Authentication Process 9 rules
T1556.003 Modify Authentication Process: Pluggable Authentication Modules 5 rules

Discovery

T1016 System Network Configuration Discovery 6 rules
T1018 Remote System Discovery 3 rules
T1033 System Owner/User Discovery 8 rules
T1040 Network Sniffing 3 rules
T1046 Network Service Discovery 12 rules
T1049 System Network Connections Discovery 3 rules
T1057 Process Discovery 11 rules
T1069 Permission Groups Discovery 2 rules
T1069.001 Permission Groups Discovery: Local Groups 2 rules
T1069.002 Permission Groups Discovery: Domain Groups 1 rule
T1082 System Information Discovery 32 rules
T1083 File and Directory Discovery 23 rules
T1087.001 Account Discovery: Local Account 2 rules
T1135 Network Share Discovery 1 rule
T1497.001 Virtualization/Sandbox Evasion: System Checks 2 rules
T1518 Software Discovery 9 rules
T1518.001 Software Discovery: Security Software Discovery 2 rules
T1580 Cloud Infrastructure Discovery 1 rule
T1613 Container and Resource Discovery 27 rules

Lateral Movement

(no specific technique) 2 rules
T1021 Remote Services 7 rules
T1021.004 Remote Services: SSH 17 rules
T1210 Exploitation of Remote Services 10 rules
T1550 Use Alternate Authentication Material 2 rules
T1550.001 Use Alternate Authentication Material: Application Access Token 2 rules
T1563.001 Remote Service Session Hijacking: SSH Hijacking 10 rules
T1570 Lateral Tool Transfer 4 rules

Collection

T1005 Data from Local System 21 rules
T1074.001 Data Staged: Local Data Staging 4 rules
T1113 Screen Capture 1 rule
T1115 Clipboard Data 1 rule
T1119 Automated Collection 5 rules
T1123 Audio Capture 1 rule
T1125 Video Capture 1 rule
T1213 Data from Information Repositories 2 rules
T1213.003 Data from Information Repositories: Code Repositories 1 rule
T1560.001 Archive Collected Data: Archive via Utility 4 rules
T1560.002 Archive Collected Data: Archive via Library 1 rule

Command & Control

(no specific technique) 3 rules
T1001 Data Obfuscation 1 rule
T1008 Fallback Channels 2 rules
T1071 Application Layer Protocol 96 rules
T1071.001 Application Layer Protocol: Web Protocols 13 rules
T1071.004 Application Layer Protocol: DNS 10 rules
T1090 Proxy 12 rules
T1090.001 Proxy: Internal Proxy 1 rule
T1090.002 Proxy: External Proxy 3 rules
T1090.003 Proxy: Multi-hop Proxy 2 rules
T1095 Non-Application Layer Protocol 15 rules
T1102 Web Service 13 rules
T1102.001 Web Service: Dead Drop Resolver 2 rules
T1102.002 Web Service: Bidirectional Communication 4 rules
T1105 Ingress Tool Transfer 30 rules
T1132 Data Encoding 1 rule
T1132.001 Data Encoding: Standard Encoding 1 rule
T1205.001 Traffic Signaling: Port Knocking 1 rule
T1219 Remote Access Tools 3 rules
T1568 Dynamic Resolution 2 rules
T1568.002 Dynamic Resolution: Domain Generation Algorithms 2 rules
T1571 Non-Standard Port 2 rules
T1572 Protocol Tunneling 19 rules
T1573.002 Encrypted Channel: Asymmetric Cryptography 1 rule

Exfiltration

(no specific technique) 1 rule
T1020 Automated Exfiltration 2 rules
T1029 Scheduled Transfer 1 rule
T1030 Data Transfer Size Limits 2 rules
T1041 Exfiltration Over C2 Channel 5 rules
T1048 Exfiltration Over Alternative Protocol 20 rules
T1048.003 Exfiltration Over Alternative Protocol: Exfiltration Over Unencrypted Non-C2 Protocol 2 rules
T1567 Exfiltration Over Web Service 1 rule
T1567.001 Exfiltration Over Web Service: Exfiltration to Code Repository 2 rules
T1567.002 Exfiltration Over Web Service: Exfiltration to Cloud Storage 2 rules
T1567.003 Exfiltration Over Web Service: Exfiltration to Text Storage Sites 2 rules

Impact

(no specific technique) 1 rule
T1485 Data Destruction 5 rules
T1486 Data Encrypted for Impact 7 rules
T1489 Service Stop 8 rules
T1490 Inhibit System Recovery 1 rule
T1496 Resource Hijacking 8 rules
T1496.001 Resource Hijacking: Compute Hijacking 1 rule
T1498 Network Denial of Service 4 rules
T1499 Endpoint Denial of Service 1 rule
T1529 System Shutdown/Reboot 5 rules
T1531 Account Access Removal 3 rules
T1565 Data Manipulation 1 rule
T1565.001 Data Manipulation: Stored Data Manipulation 3 rules

Execution

T0871 Execution through API 2 rules

(no MITRE mapping)

(no MITRE mapping) 112 rules