Analytics BIOC
Low
✕
Suspicious Udev driver rule execution manipulation
Udev driver rule was modified with unusual pattern, might be used by adversaries to backdoor existing drivers.
- Module:
- Platform Analytics
- Data source:
- XDR Agent with eXtended Threat Hunting (XTH)
ATT&CK tactics: Persistence (TA0003) Privilege Escalation (TA0004)
ATT&CK techniques: Boot or Logon Autostart Execution: Kernel Modules and Extensions (T1547.006)
Attacker's goals:
Adversaries can use this technique to execute arbitrary commands once the machine boots.
Investigative actions:
Check if the action was done using an automation service. Check the rule modification content and look for any suspicious payloads. Check if there are any other suspicious activities originated from the same machine/executing user.
- Test period:
- N/A (single event)
- Deduplication:
- 1 Day
1 variation:
- Unusual Udev driver rule execution manipulation Low