写 Debian(或 Linux 通用)exploit 检测规则,通常取决于你要在哪一层检测:
下面按常见场景给你可直接改用的模板。
alert tcp any any -> any 22 ( \
msg:"Possible sudo heap overflow exploit (CVE-2021-3156)"; \
flow:to_server; \
content:"sudoedit"; \
content:"-s"; \
content:"\\"; \
threshold:type limit, track by_src, count 1, seconds 60; \
sid:100001; rev:1; \
)
alert tcp any any -> $HOME_NET any ( \
msg:"Exploit scanning detected"; \
flow:to_server; \
content:"/etc/passwd"; \
nocase; \
sid:100002; rev:1; \
)
<rule id="100100" level="12">
<if_group>syscall</if_group>
<match>execve</match>
<match>/tmp/exploit</match>
<description>Possible exploit execution</description>
</rule>
-a always,exit -F path=/tmp -F perm=x -F auid>=1000 -k exploit_exec
SELECT * FROM suid_bin
WHERE path LIKE '/tmp/%'
OR path LIKE '/dev/shm/%';
SELECT name, version FROM deb_packages
WHERE name = 'sudo'
AND version < '1.8.27-1+deb10u3';
rule Debian_Exploit_Sample {
meta:
author = "you"
description = "Detect known Debian exploit"
strings:
$a = "/etc/shadow" ascii
$b = "CVE-2021-3156" ascii
condition:
$a and $b
}
grep -E "authentication failure|sudo:.*NOT" /var/log/auth.log
Wazuh 示例:
<rule id="100200" level="10">
<match>sudo:.*NOT in sudoers</match>
<description>Possible privilege escalation attempt</description>
</rule>
如果你能告诉我:
我可以直接帮你写精准规则。