Analytics BIOC Low

Suspicious process modified RC script file

A suspicious process modified an RC script file. These files allow system administrators to map and start custom services at startup for different run levels. This may be done to establish persistence.

Module:
Platform Analytics
Data source:
XDR Agent with eXtended Threat Hunting (XTH)
ATT&CK tactics: Persistence (TA0003) Privilege Escalation (TA0004)
ATT&CK techniques: Boot or Logon Initialization Scripts: RC Scripts (T1037.004)
Detector tags: Kubernetes - AGENT Containers
Attacker's goals:

Adversaries may establish persistence by modifying RC scripts, which are executed during a Unix-like system's startup.

Investigative actions:

Check the modified RC script file and try to understand the impact of the file modification.

Test period:
N/A (single event)
Deduplication:
1 Day
1 variation:
  • Suspicious process modified RC script file in a Kubernetes pod Low