Detection rules › Elastic
Egress Network Connection from Default DPKG Directory
This rule monitors for network connections from processes that are executed from the /var/lib/dpkg/info/ directory. This directory is used to store information about installed packages. Attackers can backdoor the installation scripts of packages to establish network connections during the installation process to maintain persistence or to establish command and control.
MITRE ATT&CK coverage
| Tactic | Techniques |
|---|---|
| Initial Access | |
| Execution | |
| Persistence | |
| Stealth | |
| Command & Control |
Rule body
[rule]
description = """
This rule monitors for network connections from processes that are executed from the /var/lib/dpkg/info/ directory. This
directory is used to store information about installed packages. Attackers can backdoor the installation scripts of
packages to establish network connections during the installation process to maintain persistence or to establish
command and control.
"""
id = "947b70bb-8e01-4f1b-994d-5af9488556bb"
license = "Elastic License v2"
name = "Egress Network Connection from Default DPKG Directory"
os_list = ["linux"]
reference = ["https://www.makeuseof.com/how-deb-packages-are-backdoored-how-to-detect-it/"]
version = "1.0.10"
query = '''
sequence with maxspan=3s
[process where event.type == "start" and event.action == "exec" and
process.parent.executable like "/var/lib/dpkg/info/*" and not (
process.executable like ("/usr/sbin/runuser", "/opt/vivaldi/*", "/usr/bin/syslog-ng-update-virtualenv") or
process.parent.executable == "/var/lib/dpkg/info/falco.postinst" or
process.parent.executable like (
"/var/lib/dpkg/info/percona-server-server-*.postinst", "/var/lib/dpkg/info/vivaldi*",
"/var/lib/dpkg/info/percona-xtradb-cluster-server*", "/var/lib/dpkg/info/univention-updater*",
"/var/lib/dpkg/info/microsoft-edge-beta.postinst"
) or
process.parent.name in ("mdatp.postinst", "mdatp.postrm") or
process.args like ("/var/lib/dpkg/info/percona-xtradb-cluster-server-*.postinst", "/etc/cron.daily/*")
)
] by process.entity_id
[network where event.type == "start" and event.action == "connection_attempted" and not (
destination.ip == null or
destination.ip == "0.0.0.0" or
cidrmatch(
destination.ip, "10.0.0.0/8", "127.0.0.0/8", "169.254.0.0/16", "172.16.0.0/12", "192.0.0.0/24", "192.0.0.0/29",
"192.0.0.8/32", "192.0.0.9/32", "192.0.0.10/32", "192.0.0.170/32", "192.0.0.171/32", "192.0.2.0/24",
"192.31.196.0/24", "192.52.193.0/24", "192.168.0.0/16", "192.88.99.0/24", "224.0.0.0/4", "100.64.0.0/10",
"192.175.48.0/24","198.18.0.0/15", "198.51.100.0/24", "203.0.113.0/24", "240.0.0.0/4", "::1", "FE80::/10",
"FF00::/8", "172.31.0.0/16"
) or
process.executable in (
"/usr/bin/apt-get", "/bin/apt-get", "/opt/cisco/amp/etc/ampinsthelper", "/opt/teleport/system/bin/tsh",
"/usr/lib/apt/methods/https"
)
)] by process.parent.entity_id
'''
min_endpoint_version = "8.6.0"
optional_actions = []
[[actions]]
action = "kill_process"
field = "process.entity_id"
state = 1
[[threat]]
framework = "MITRE ATT&CK"
[[threat.technique]]
id = "T1195"
name = "Supply Chain Compromise"
reference = "https://attack.mitre.org/techniques/T1195/"
[[threat.technique.subtechnique]]
id = "T1195.002"
name = "Compromise Software Supply Chain"
reference = "https://attack.mitre.org/techniques/T1195/002/"
[threat.tactic]
id = "TA0001"
name = "Initial Access"
reference = "https://attack.mitre.org/tactics/TA0001/"
[[threat]]
framework = "MITRE ATT&CK"
[[threat.technique]]
id = "T1543"
name = "Create or Modify System Process"
reference = "https://attack.mitre.org/techniques/T1543/"
[[threat.technique]]
id = "T1546"
name = "Event Triggered Execution"
reference = "https://attack.mitre.org/techniques/T1546/"
[[threat.technique.subtechnique]]
id = "T1546.016"
name = "Installer Packages"
reference = "https://attack.mitre.org/techniques/T1546/016/"
[[threat.technique]]
id = "T1574"
name = "Hijack Execution Flow"
reference = "https://attack.mitre.org/techniques/T1574/"
[threat.tactic]
id = "TA0003"
name = "Persistence"
reference = "https://attack.mitre.org/tactics/TA0003/"
[[threat]]
framework = "MITRE ATT&CK"
[[threat.technique]]
id = "T1071"
name = "Application Layer Protocol"
reference = "https://attack.mitre.org/techniques/T1071/"
[threat.tactic]
id = "TA0011"
name = "Command and Control"
reference = "https://attack.mitre.org/tactics/TA0011/"
[internal]
min_endpoint_version = "8.6.0"
Stages and Predicates
Ordered sequence: each step below must occur in order within 3s, correlated by process.entity_id, process.parent.entity_id.
Stage 1: process
[process where event.type == "start" and event.action == "exec" and
process.parent.executable like "/var/lib/dpkg/info/*" and not (
process.executable like ("/usr/sbin/runuser", "/opt/vivaldi/*", "/usr/bin/syslog-ng-update-virtualenv") or
process.parent.executable == "/var/lib/dpkg/info/falco.postinst" or
process.parent.executable like (
"/var/lib/dpkg/info/percona-server-server-*.postinst", "/var/lib/dpkg/info/vivaldi*",
"/var/lib/dpkg/info/percona-xtradb-cluster-server*", "/var/lib/dpkg/info/univention-updater*",
"/var/lib/dpkg/info/microsoft-edge-beta.postinst"
) or
process.parent.name in ("mdatp.postinst", "mdatp.postrm") or
process.args like ("/var/lib/dpkg/info/percona-xtradb-cluster-server-*.postinst", "/etc/cron.daily/*")
)
] by process.entity_id
Stage 2: network
[network where event.type == "start" and event.action == "connection_attempted" and not (
destination.ip == null or
destination.ip == "0.0.0.0" or
cidrmatch(
destination.ip, "10.0.0.0/8", "127.0.0.0/8", "169.254.0.0/16", "172.16.0.0/12", "192.0.0.0/24", "192.0.0.0/29",
"192.0.0.8/32", "192.0.0.9/32", "192.0.0.10/32", "192.0.0.170/32", "192.0.0.171/32", "192.0.2.0/24",
"192.31.196.0/24", "192.52.193.0/24", "192.168.0.0/16", "192.88.99.0/24", "224.0.0.0/4", "100.64.0.0/10",
"192.175.48.0/24","198.18.0.0/15", "198.51.100.0/24", "203.0.113.0/24", "240.0.0.0/4", "::1", "FE80::/10",
"FF00::/8", "172.31.0.0/16"
) or
process.executable in (
"/usr/bin/apt-get", "/bin/apt-get", "/opt/cisco/amp/etc/ampinsthelper", "/opt/teleport/system/bin/tsh",
"/usr/lib/apt/methods/https"
)
)] by process.parent.entity_id
Exclusions
The rule actively suppresses these predicates.
| Field | Kind | Excluded values | Search |
|---|---|---|---|
process.args | wildcard | /var/lib/dpkg/info/percona-xtradb-cluster-server-*.postinst, /etc/cron.daily/* | excludes:process.args field:"process.args" value:"/var/lib/dpkg/info/percona-xtradb-cluster-server-*.postinst" field:"process.args" value:"/etc/cron.daily/*" |
process.executable | wildcard | /usr/sbin/runuser, /opt/vivaldi/*, /usr/bin/syslog-ng-update-virtualenv | excludes:process.executable field:"process.executable" value:"/usr/sbin/runuser" field:"process.executable" value:"/opt/vivaldi/*" field:"process.executable" value:"/usr/bin/syslog-ng-update-virtualenv" |
process.parent.executable | eq | /var/lib/dpkg/info/falco.postinst | excludes:process.parent.executable field:"process.parent.executable" value:"/var/lib/dpkg/info/falco.postinst" |
process.parent.executable | wildcard | /var/lib/dpkg/info/percona-server-server-*.postinst, /var/lib/dpkg/info/vivaldi*, /var/lib/dpkg/info/percona-xtradb-cluster-server*, /var/lib/dpkg/info/univention-updater*, /var/lib/dpkg/info/microsoft-edge-beta.postinst | excludes:process.parent.executable |
process.parent.name | in | mdatp.postinst, mdatp.postrm | excludes:process.parent.name field:"process.parent.name" value:"mdatp.postinst" field:"process.parent.name" value:"mdatp.postrm" |
destination.ip | cidr_match | 10.0.0.0/8, 127.0.0.0/8, 169.254.0.0/16, 172.16.0.0/12, 192.0.0.0/24, 192.0.0.0/29, 192.0.0.8/32, 192.0.0.9/32, 192.0.0.10/32, 192.0.0.170/32, 192.0.0.171/32, 192.0.2.0/24, 192.31.196.0/24, 192.52.193.0/24, 192.168.0.0/16, 192.88.99.0/24, 224.0.0.0/4, 100.64.0.0/10, 192.175.48.0/24, 198.18.0.0/15, 198.51.100.0/24, 203.0.113.0/24, 240.0.0.0/4, ::1, FE80::/10, FF00::/8, 172.31.0.0/16 | excludes:destination.ip |
destination.ip | eq | 0.0.0.0 | excludes:destination.ip field:"destination.ip" value:"0.0.0.0" |
destination.ip | is_null | excludes:destination.ip | |
process.executable | in | /bin/apt-get, /opt/cisco/amp/etc/ampinsthelper, /opt/teleport/system/bin/tsh, /usr/bin/apt-get, /usr/lib/apt/methods/https | excludes:process.executable |
Indicators
These rows show field, operator, and value matches.
| Field | Kind | Values | Search |
|---|---|---|---|
event.action | eq |
| field:"EventType" kind:eq |
event.type | eq |
| field:"event.type" kind:eq value:"start" |
process.parent.executable | wildcard |
| field:"ParentImage" kind:wildcard value:"/var/lib/dpkg/info/*" |