Event Triggered Execution: Installer Packages T1546.016

Tactics: Privilege Escalation, Persistence

Adversaries may establish persistence and elevate privileges by using an installer to trigger the execution of malicious content. Installer packages are OS specific and contain the resources an operating system needs to install applications on a system. Installer packages can include scripts that run prior to installation as well as after installation is complete. Installer scripts may inherit elevated permissions when executed. Developers often use these scripts to prepare the environment for installation, check requirements, download dependencies, and remove files after installation.

Events covered

1 catalog event is tagged with this technique by at least one rule.

ProviderEventTitle
ESFexecProcess Execution

Authoring guide

These 15 rules share fields, values, and exclusions.

Fields filtered most (23 distinct)

These fields appear most often in rule filters.

FieldRulesHowSample values
EventType14eq 8, in 4, ne 2exec, connection_attempted, creation, rename, deletion
event.type12eq 12start
host.os.type9eq 9
process_name8in 5, eq 2, wildcard 2bash, cp, csh, mv, awk
TargetFilename5starts_with 3, wildcard 2/etc/apt/apt.conf.d/, /etc/dnf/plugins/*, /etc/yum/pluginconf.d/, /library/containers/*, /library/fonts/
parent_process_name5eq 2, in 2, wildcard 1bash, apt, csh, dash, sh
process.args5eq 2, in 2, starts_with 1, wildcard 1--install, -c, -i, /Users/, /Volumes/
Image2starts_with 1, wildcard 1./*, /boot/*, /dev/shm/*, /var/lib/dpkg/info/
event.category2eq 2process
file.Ext.header_bytes2starts_with 2cafebabe, cffaedfe
process.code_signature.exists2eq 2false
process.code_signature.trusted2eq 2false
ParentImage1starts_with 1/var/lib/dpkg/info/
Persistence.args1wildcard 1/Applications/*, /Library/Application Support/*, /Users/*/Library/Application Support/*
event0.Persistence.args1starts_with 1process.executable

Top indicator values (135 distinct)

These values appear most often in rule predicates.

FieldKindValueRules (here)Corpus reach
event.typeeq
start
121087
EventTypeeq
exec
8579
EventTypeeq
connection_attempted
475
EventTypein
creation
334
EventTypein
rename
327
process_namein
bash
3202
process_namein
cp
318
process_namein
mv
316
process_namein
sh
3197
process_namein
zsh
3196
process_namein
csh
2159
process_namein
dash
2170
process_namein
fish
2163
process_namein
ksh
2163
process_namein
tcsh
2156
EventTypene
deletion
287
event.categoryeq
process
2141
file.Ext.header_bytesstarts_with
cafebabe
219
file.Ext.header_bytesstarts_with
cffaedfe
219
parent_process_nameeq
apt
22
parent_process_namein
bash
266
parent_process_namein
sh
266
parent_process_namein
zsh
264
process.argseq
-c
2107
process.argsin
--install
23
process.argsin
-i
210
process.code_signature.existseq
false
2119
process.code_signature.trustedeq
false
2115
process_namewildcard
awk
27
process_namewildcard
bash
239

Exclusions (235 distinct)

These values appear most often in top-level exclusions.

FieldKindValueRules excluding
dest_ipcidr_match
10.0.0.0/8
4
dest_ipcidr_match
100.64.0.0/10
4
dest_ipcidr_match
127.0.0.0/8
4
dest_ipcidr_match
169.254.0.0/16
4
dest_ipcidr_match
172.16.0.0/12
4
dest_ipcidr_match
172.31.0.0/16
4
dest_ipcidr_match
192.0.0.0/24
4
dest_ipcidr_match
192.0.0.0/29
4
dest_ipcidr_match
192.0.0.10/32
4
dest_ipcidr_match
192.0.0.170/32
4
dest_ipcidr_match
192.0.0.171/32
4
dest_ipcidr_match
192.0.0.8/32
4
dest_ipcidr_match
192.0.0.9/32
4
dest_ipcidr_match
192.0.2.0/24
4
dest_ipcidr_match
192.168.0.0/16
4

Rules under this technique

These vendors publish rules tagged with this technique.

Domain: Endpoint

Platform (all)

Elastic 15 rules