Detection rules › Elastic
Curl Execution via Automator Application
Detects the execution of curl via an automator application. Threat actors have been using automator applications in order to bypass security controls and download second stage payloads as automator apps can be signed/trusted by the system and are generally not subject to scanning.
MITRE ATT&CK coverage
| Tactic | Techniques |
|---|---|
| Command & Control |
Rule body
[rule]
description = """
Detects the execution of curl via an automator application. Threat actors have been using automator applications in
order to bypass security controls and download second stage payloads as automator apps can be signed/trusted by the
system and are generally not subject to scanning.
"""
id = "3540b77a-80a6-42ea-b7f4-714291a28a62"
license = "Elastic License v2"
name = "Curl Execution via Automator Application"
os_list = ["macos"]
version = "1.0.5"
query = '''
process where event.type == "start" and process.parent.name in ("Application Stub", "Automator Application Stub") and
(
(process.name like~ ("sh", "bash", "zsh", "tclsh*") and
process.args == "-c" and
process.args like~ ("curl*", "nscurl*")) or
(process.name in ("curl", "nscurl"))
)
'''
min_endpoint_version = "8.7.0"
optional_actions = []
[[actions]]
action = "kill_process"
field = "process.entity_id"
state = 0
[[actions]]
action = "kill_process"
field = "process.parent.entity_id"
state = 0
[[threat]]
framework = "MITRE ATT&CK"
[[threat.technique]]
id = "T1105"
name = "Ingress Tool Transfer"
reference = "https://attack.mitre.org/techniques/T1105/"
[threat.tactic]
id = "TA0011"
name = "Command and Control"
reference = "https://attack.mitre.org/tactics/TA0011/"
[internal]
min_endpoint_version = "8.7.0"
Stages and Predicates
Stage 1: process
process where event.type == "start" and process.parent.name in ("Application Stub", "Automator Application Stub") and
(
(process.name like~ ("sh", "bash", "zsh", "tclsh*") and
process.args == "-c" and
process.args like~ ("curl*", "nscurl*")) or
(process.name in ("curl", "nscurl"))
)
Indicators
These rows show field, operator, and value matches.
| Field | Kind | Values | Search |
|---|---|---|---|
event.type | eq |
| field:"event.type" kind:eq value:"start" |
process.args | eq |
| field:"process.args" kind:eq value:"-c" |
process.args | wildcard |
| field:"process.args" kind:wildcard |
process.name | in |
| field:"process_name" kind:in |
process.name | wildcard |
| field:"process_name" kind:wildcard |
process.parent.name | in |
| field:"parent_process_name" kind:in |