Sigma Rule Library

BPFDoor Abnormal Process ID or Lock File Accessed

detects BPFDoor .lock and .pid files access in temporary file storage facility

View on GitHubOpen raw file

Detection logic

selection

type: PATH
name:
  - /var/run/aepmonend.pid
  - /var/run/auditd.lock
  - /var/run/cma.lock
  - /var/run/console-kit.pid
  - /var/run/consolekit.pid
  - /var/run/daemon.pid
  - /var/run/hald-addon.pid
  - /var/run/hald-smartd.pid
  - /var/run/haldrund.pid
  - /var/run/hp-health.pid
  - /var/run/hpasmlit.lock
  - /var/run/hpasmlited.pid
  - /var/run/kdevrund.pid
  - /var/run/lldpad.lock
  - /var/run/mcelog.pid
  - /var/run/system.pid
  - /var/run/uvp-srv.pid
  - /var/run/vmtoolagt.pid
  - /var/run/xinetd.lock

Condition

selection

Raw YAML

title: BPFDoor Abnormal Process ID or Lock File Accessed
id: 808146b2-9332-4d78-9416-d7e47012d83d
status: test
description: detects BPFDoor .lock and .pid files access in temporary file storage facility
references:
    - https://www.sandflysecurity.com/blog/bpfdoor-an-evasive-linux-backdoor-technical-analysis/
    - https://www.elastic.co/security-labs/a-peek-behind-the-bpfdoor
    - https://www.rapid7.com/blog/post/tr-bpfdoor-telecom-networks-sleeper-cells-threat-research-report/
    - https://github.com/rapid7/Rapid7-Labs/blob/741c7196ec12a0a56b63463d1fd726ff14d3a97a/BPFDoor/rapid7_detect_bpfdoor.sh
author: Rafal Piasecki
date: 2022-08-10
modified: 2026-03-30
tags:
    - attack.execution
    - attack.t1106
    - attack.t1059
logsource:
    product: linux
    service: auditd
detection:
    selection:
        type: 'PATH'
        name:
            - /var/run/aepmonend.pid
            - /var/run/auditd.lock
            - /var/run/cma.lock
            - /var/run/console-kit.pid
            - /var/run/consolekit.pid
            - /var/run/daemon.pid
            - /var/run/hald-addon.pid
            - /var/run/hald-smartd.pid
            - /var/run/haldrund.pid
            - /var/run/hp-health.pid
            - /var/run/hpasmlit.lock
            - /var/run/hpasmlited.pid
            - /var/run/kdevrund.pid
            - /var/run/lldpad.lock
            - /var/run/mcelog.pid
            - /var/run/system.pid
            - /var/run/uvp-srv.pid
            - /var/run/vmtoolagt.pid
            - /var/run/xinetd.lock
    condition: selection
falsepositives:
    - Unlikely
level: high

False positives

  • Unlikely

References

Similar rules