Detection rules › Sigma

Python Spawning Pretty TTY Via PTY Module

Status
test
Severity
medium
Log source
category process_creation, product linux
Author
Nextron Systems
Source
github.com/SigmaHQ/sigma

Detects a python process calling to the PTY module in order to spawn a pretty tty which could be indicative of potential reverse shell activity.

MITRE ATT&CK coverage

Telemetry coverage

PlatformRecord / event type
LinuxEvent ID 1: Process Create

Rule body

title: Python Spawning Pretty TTY Via PTY Module
id: c4042d54-110d-45dd-a0e1-05c47822c937
related:
    - id: 32e62bc7-3de0-4bb1-90af-532978fe42c0
      type: similar
status: test
description: |
    Detects a python process calling to the PTY module in order to spawn a pretty tty which could be indicative of potential reverse shell activity.
references:
    - https://www.volexity.com/blog/2022/06/02/zero-day-exploitation-of-atlassian-confluence/
author: Nextron Systems
date: 2022-06-03
modified: 2024-11-04
tags:
    - attack.execution
    - attack.t1059
logsource:
    category: process_creation
    product: linux
detection:
    selection_img:
        - Image|endswith:
              - '/python'
              - '/python2'
              - '/python3'
        - Image|contains:
              - '/python2.'  # python image is always of the form ../python3.10; ../python is just a symlink
              - '/python3.'
    selection_cli_import:
        CommandLine|contains:
            - 'import pty'
            - 'from pty '
    selection_cli_spawn:
        CommandLine|contains: 'spawn'
    condition: all of selection_*
falsepositives:
    - Unknown
level: medium

Stages and Predicates

Stage 0: condition

all of selection_*

Stage 1: selection_img

selection_img:
    - Image|endswith:
          - '/python'
          - '/python2'
          - '/python3'
    - Image|contains:
          - '/python2.'
          - '/python3.'

Stage 2: selection_cli_import

selection_cli_import:
    CommandLine|contains:
        - 'import pty'
        - 'from pty '

Stage 3: selection_cli_spawn

selection_cli_spawn:
    CommandLine|contains: 'spawn'

Indicators

These rows show field, operator, and value matches.

FieldKindValuesSearch
CommandLinematch
  • from pty
  • import pty
  • spawn
field:"CommandLine" kind:match
Imageends_with
  • /python
  • /python2
  • /python3
field:"Image" kind:ends_with
Imagematch
  • /python2.
  • /python3.
field:"Image" kind:match