Detection rules › Elastic
Python Script Execution via Shell and Remote Network Connection
This rule looks for the specific behavior exhibited when the Python sample utilizes the subprocess.Popen method, setting the shell variable equal to True, in order to execute an embedded Python script that connects to a remote server in order to retrieve and execute a command which gets written to a temporary file and executed.
MITRE ATT&CK coverage
| Tactic | Techniques |
|---|---|
| Execution | |
| Command & Control |
Telemetry coverage
Rule body
[rule]
description = """
This rule looks for the specific behavior exhibited when the Python sample utilizes the subprocess.Popen method, setting
the shell variable equal to True, in order to execute an embedded Python script that connects to a remote server in
order to retrieve and execute a command which gets written to a temporary file and executed.
"""
id = "f5c2b536-d7a7-4724-a149-a7e717e40429"
license = "Elastic License v2"
name = "Python Script Execution via Shell and Remote Network Connection"
os_list = ["macos"]
reference = [
"https://www.reversinglabs.com/blog/fake-recruiter-coding-tests-target-devs-with-malicious-python-packages",
]
version = "1.0.8"
query = '''
sequence by process.parent.entity_id with maxspan=3s
[process where event.type == "start" and event.action == "exec" and process.parent.name like~ "python*" and
process.name in ("sh", "zsh", "bash") and process.args == "-c" and process.args like~ "python*" and
process.args like~ "*.py" and process.args_count == 3 and
not process.command_line like~ "* pip*"]
[network where event.type == "start" and
not cidrmatch(destination.ip,
"240.0.0.0/4", "233.252.0.0/24", "224.0.0.0/4", "198.19.0.0/16", "192.18.0.0/15",
"192.0.0.0/24", "10.0.0.0/8", "127.0.0.0/8", "169.254.0.0/16", "172.16.0.0/12",
"192.0.2.0/24", "192.31.196.0/24", "192.52.193.0/24", "192.168.0.0/16", "192.88.99.0/24",
"100.64.0.0/10", "192.175.48.0/24", "198.18.0.0/15", "198.51.100.0/24", "203.0.113.0/24",
"::1", "FE80::/10", "FF00::/8")]
'''
min_endpoint_version = "8.16.0"
optional_actions = []
[[actions]]
action = "kill_process"
field = "process.entity_id"
state = 0
[[actions]]
action = "kill_process"
field = "process.parent.entity_id"
state = 0
[[threat]]
framework = "MITRE ATT&CK"
[[threat.technique]]
id = "T1059"
name = "Command and Scripting Interpreter"
reference = "https://attack.mitre.org/techniques/T1059/"
[[threat.technique.subtechnique]]
id = "T1059.006"
name = "Python"
reference = "https://attack.mitre.org/techniques/T1059/006/"
[threat.tactic]
id = "TA0002"
name = "Execution"
reference = "https://attack.mitre.org/tactics/TA0002/"
[[threat]]
framework = "MITRE ATT&CK"
[[threat.technique]]
id = "T1105"
name = "Ingress Tool Transfer"
reference = "https://attack.mitre.org/techniques/T1105/"
[threat.tactic]
id = "TA0011"
name = "Command and Control"
reference = "https://attack.mitre.org/tactics/TA0011/"
[internal]
min_endpoint_version = "8.16.0"
Stages and Predicates
Ordered sequence: each step below must occur in order within 3s, correlated by process.parent.entity_id.
Stage 1: process
[process where event.type == "start" and event.action == "exec" and process.parent.name like~ "python*" and
process.name in ("sh", "zsh", "bash") and process.args == "-c" and process.args like~ "python*" and
process.args like~ "*.py" and process.args_count == 3 and
not process.command_line like~ "* pip*"]
Stage 2: network
[network where event.type == "start" and
not cidrmatch(destination.ip,
"240.0.0.0/4", "233.252.0.0/24", "224.0.0.0/4", "198.19.0.0/16", "192.18.0.0/15",
"192.0.0.0/24", "10.0.0.0/8", "127.0.0.0/8", "169.254.0.0/16", "172.16.0.0/12",
"192.0.2.0/24", "192.31.196.0/24", "192.52.193.0/24", "192.168.0.0/16", "192.88.99.0/24",
"100.64.0.0/10", "192.175.48.0/24", "198.18.0.0/15", "198.51.100.0/24", "203.0.113.0/24",
"::1", "FE80::/10", "FF00::/8")]
Exclusions
The rule actively suppresses these predicates.
| Field | Kind | Excluded values | Search |
|---|---|---|---|
process.command_line | match | pip | excludes:process.command_line field:"process.command_line" value:" pip" |
destination.ip | cidr_match | 240.0.0.0/4, 233.252.0.0/24, 224.0.0.0/4, 198.19.0.0/16, 192.18.0.0/15, 192.0.0.0/24, 10.0.0.0/8, 127.0.0.0/8, 169.254.0.0/16, 172.16.0.0/12, 192.0.2.0/24, 192.31.196.0/24, 192.52.193.0/24, 192.168.0.0/16, 192.88.99.0/24, 100.64.0.0/10, 192.175.48.0/24, 198.18.0.0/15, 198.51.100.0/24, 203.0.113.0/24, ::1, FE80::/10, FF00::/8 | excludes:destination.ip |
Indicators
These rows show field, operator, and value matches.