2022-10-14 19:14:24 +00:00
|
|
|
-- Find unexpected executables in /var
|
|
|
|
--
|
|
|
|
-- false positives:
|
|
|
|
-- * none known
|
|
|
|
--
|
|
|
|
-- tags: persistent
|
|
|
|
-- platform: linux
|
2022-11-03 15:51:54 +00:00
|
|
|
SELECT
|
|
|
|
file.path,
|
2022-10-14 19:14:24 +00:00
|
|
|
file.directory,
|
|
|
|
uid,
|
|
|
|
gid,
|
|
|
|
mode,
|
|
|
|
file.mtime,
|
|
|
|
file.size,
|
|
|
|
hash.sha256,
|
|
|
|
magic.data
|
2022-11-03 15:51:54 +00:00
|
|
|
FROM
|
|
|
|
file
|
2022-10-14 19:14:24 +00:00
|
|
|
LEFT JOIN hash on file.path = hash.path
|
|
|
|
LEFT JOIN magic ON file.path = magic.path
|
2022-11-03 15:51:54 +00:00
|
|
|
WHERE
|
|
|
|
(
|
2022-10-14 19:14:24 +00:00
|
|
|
-- This list is the result of multiple queries combined and can likely be minimized
|
|
|
|
file.path LIKE '/var/%%'
|
|
|
|
OR file.path LIKE '/var/tmp/%%'
|
|
|
|
OR file.path LIKE '/var/tmp/.%/%%'
|
|
|
|
OR file.path LIKE '/var/tmp/%/%%'
|
|
|
|
OR file.path LIKE '/var/tmp/%/%/.%'
|
|
|
|
OR file.path LIKE '/var/tmp/%/.%/%%'
|
|
|
|
OR file.path LIKE '/var/spool/%%'
|
|
|
|
OR file.path LIKE '/var/spool/.%/%%'
|
|
|
|
OR file.path LIKE '/var/spool/%/%%'
|
|
|
|
OR file.path LIKE '/var/spool/%/%/.%'
|
|
|
|
OR file.path LIKE '/var/spool/%/.%/%%'
|
|
|
|
)
|
|
|
|
AND file.type = 'regular'
|
|
|
|
AND file.path NOT LIKE '%/../%'
|
|
|
|
AND file.path NOT LIKE '%/./%'
|
|
|
|
AND (
|
|
|
|
file.mode LIKE '%7%'
|
2022-10-31 21:40:37 +00:00
|
|
|
OR file.mode LIKE '%5%'
|
|
|
|
OR file.mode LIKE '%1%'
|
2022-10-14 19:14:24 +00:00
|
|
|
)
|
|
|
|
AND file.directory NOT IN (
|
|
|
|
'/var/lib/colord',
|
|
|
|
'/var/ossec/agentless',
|
|
|
|
'/var/ossec/bin',
|
|
|
|
'/var/ossec/wodles',
|
|
|
|
'/var/run/booted-system',
|
|
|
|
'/var/run/current-system'
|
|
|
|
)
|
2023-02-21 00:10:12 +00:00
|
|
|
AND file.path NOT IN (
|
|
|
|
'/var/run/lima-boot-done',
|
|
|
|
'/var/run/lima-ssh-ready'
|
|
|
|
)
|
2023-09-25 02:02:34 +00:00
|
|
|
AND (
|
|
|
|
magic.data IS NULL
|
|
|
|
OR magic.data != 'JSON data'
|
|
|
|
)
|
2022-11-03 15:51:54 +00:00
|
|
|
AND file.size > 10
|