diff --git a/detections/endpoint/python_network_traffic_during_package_build.yml b/detections/endpoint/python_network_traffic_during_package_build.yml new file mode 100644 index 0000000000..4764715371 --- /dev/null +++ b/detections/endpoint/python_network_traffic_during_package_build.yml @@ -0,0 +1,67 @@ +name: Python Network Traffic during Package Build +id: 03c9c504-2294-44da-8180-beefe1ca8ba8 +version: 1 +creation_date: '2026-07-23' +modification_date: '2026-07-23' +author: Onur Mustafa Erdogan, Splunk +status: production +type: TTP +description: |- + The following analytic detects a Python process making an outbound network connection during package installation. + Adversaries can abuse `setup.py` build scripts by leveraging `distutils`/`setuptools` command classes to execute arbitrary code, + including network beacons to third-party domains, the moment a malicious Python package is installed. This activity is significant + because it allows adversaries to establish a foothold or exfiltrate data without any direct interaction from the victim beyond + running `pip install`. If confirmed malicious, this could indicate a successful software supply chain compromise. +data_source: + - Sysmon EventID 1 + - Sysmon EventID 3 +search: |- + `sysmon` EventID IN (1,3) + | bin _time span=5m + | stats values(parent_process_id) as parent_process_id, values(dest_ip) as dest_ip, values(QueryName) as QueryName, values(CommandLine) as CommandLine, values(parent_process) as parent_process, dc(EventID) as EventID count by _time, host, source, process_id + | search CommandLine="*_in_process.py*" AND CommandLine="* build_wheel*" AND dest_ip!="" + | `python_network_traffic_during_package_build_filter` +how_to_implement: |- + The detection is based on data that originates from Sysmon. To implement this search, you must ingest logs + with process creation (EventID 1) and network connection (EventID 3) events, mapped via the appropriate + Splunk Technology Add-on. Use the Splunk Common Information Model (CIM) to normalize the field names. +known_false_positives: Python packages may contact software repositories, mirror sites during build time. Investigate the destination and package content to determine legitimacy. +references: + - https://blog.talosintelligence.com/the-serpents-tongue-luring-the-python-out-of-its-den/ +drilldown_searches: + - name: View the detection results for - "$host$" + search: '%original_detection_search% | search host = "$host$"' + earliest_offset: $info_min_time$ + latest_offset: $info_max_time$ + - name: View risk events for the last 7 days for - "$host$" + search: '| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$host$") | stats count min(_time) as firstTime max(_time) as lastTime values(search_name) as "Search Name" values(risk_message) as "Risk Message" values(analyticstories) as "Analytic Stories" values(annotations._all) as "Annotations" values(annotations.mitre_attack.mitre_tactic) as "ATT&CK Tactics" by normalized_risk_object | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`' + earliest_offset: 7d + latest_offset: "0" +finding: + title: A Python process on $host$ made an outbound network connection to $dest$ during package installation + entity: + field: host + type: system + score: 30 +analytic_story: + - Malicious Python Package Installation + - Ingress Tool Transfer + - Command And Control + - Compromised Windows Host +asset_type: Endpoint +mitre_attack_id: + - T1195.002 + - T1059.006 +product: + - Splunk Enterprise + - Splunk Enterprise Security + - Splunk Cloud +category: endpoint +security_domain: endpoint +tests: + - name: True Positive Test + attack_data: + - data: https://raw.githubusercontent.com/splunk/attack_data/refs/heads/master/datasets/attack_techniques/T1195.002/python_network_traffic/python_network_traffic.log + source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational + sourcetype: XmlWinEventLog + test_type: unit diff --git a/detections/endpoint/python_pth_file_creation_during_package_installation.yml b/detections/endpoint/python_pth_file_creation_during_package_installation.yml new file mode 100644 index 0000000000..58c3d17876 --- /dev/null +++ b/detections/endpoint/python_pth_file_creation_during_package_installation.yml @@ -0,0 +1,70 @@ +name: Python PTH File Creation during Package Installation +id: bf581b86-39cd-48b7-9312-d9affb48a8bc +version: 1 +creation_date: '2026-07-23' +modification_date: '2026-07-23' +author: Onur Mustafa Erdogan, Splunk +status: production +type: TTP +description: |- + The following analytic detects the creation of a Python path configuration (`.pth`) file in conjunction + with a package installation process. Path configuration files placed under `site-packages` or `dist-packages` + are executed with every subsequent invocation of Python, allowing adversaries to achieve persistence + on the victim endpoint regardless of build method or distribution type. This technique was used by the + threat actor group TeamPCP during the supply chain compromise of the `litellm` package. If confirmed + malicious, this could result in arbitrary code execution every time Python is invoked on the compromised host. +data_source: + - Sysmon EventID 1 + - Sysmon EventID 11 +search: |- + `sysmon` EventID IN (1,11) AND (CommandLine="* install *" OR (TargetFilename="*.pth" AND action="created")) + | bin _time span=5m + | stats values(parent_process_id) as parent_process_id, values(TargetFilename) as TargetFilename, values(CommandLine) as CommandLine, values(parent_process) as parent_process, dc(EventID) as dc_event_id count by _time, host, source, process_id + | search dc_event_id>1 + | `python_pth_file_creation_during_package_installation_filter` +how_to_implement: |- + This detection requires Sysmon event logs. Configure your environment to ingest Sysmon process creation (EventID 1) + and file creation (EventID 11) events, ensuring that file creation events are collected for files with the .pth + extension. Ingest the data via the appropriate Splunk Technology Add-on and normalize field names using the + Splunk Common Information Model (CIM). +known_false_positives: |- + Legitimate packages, such as those managing namespace packages or editable installs, may create `.pth` + files as part of normal installation. Investigate the file contents and parent process to determine legitimacy. +references: + - https://blog.talosintelligence.com/the-serpents-tongue-luring-the-python-out-of-its-den/ +drilldown_searches: + - name: View the detection results for - "$host$" + search: '%original_detection_search% | search host = "$host$"' + earliest_offset: $info_min_time$ + latest_offset: $info_max_time$ + - name: View risk events for the last 7 days for - "$host$" + search: '| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$host$") | stats count min(_time) as firstTime max(_time) as lastTime values(search_name) as "Search Name" values(risk_message) as "Risk Message" values(analyticstories) as "Analytic Stories" values(annotations._all) as "Annotations" values(annotations.mitre_attack.mitre_tactic) as "ATT&CK Tactics" by normalized_risk_object | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`' + earliest_offset: 7d + latest_offset: "0" +finding: + title: A Python `.pth` file called $TargetFilename$ was created on $host$ during package installation + entity: + field: host + type: system + score: 40 +analytic_story: + - Malicious Python Package Installation + - Compromised Windows Host + - Windows Persistence Techniques +asset_type: Endpoint +mitre_attack_id: + - T1546 + - T1195.002 +product: + - Splunk Enterprise + - Splunk Enterprise Security + - Splunk Cloud +category: endpoint +security_domain: endpoint +tests: + - name: True Positive Test + attack_data: + - data: https://raw.githubusercontent.com/splunk/attack_data/refs/heads/master/datasets/attack_techniques/T1546/python_pth_file_creation/python_pth_file_creation.log + source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational + sourcetype: XmlWinEventLog + test_type: unit diff --git a/detections/endpoint/python_pythonpath_modification_during_package_installation.yml b/detections/endpoint/python_pythonpath_modification_during_package_installation.yml new file mode 100644 index 0000000000..a54467e4cf --- /dev/null +++ b/detections/endpoint/python_pythonpath_modification_during_package_installation.yml @@ -0,0 +1,74 @@ +name: Python PYTHONPATH Modification During Package Installation +id: 00f01ba4-df01-4caa-90f6-187e4563a516 +version: 1 +creation_date: '2026-07-23' +modification_date: '2026-07-23' +author: Onur Mustafa Erdogan, Splunk +status: production +type: TTP +description: |- + The following analytic detects modification of the PYTHONPATH environment variable in conjunction + with a package installation process. Python looks up the `sys.path` variable, which is generated + by combining user and site folders with `.pth` files and the value of the PYTHONPATH environment + variable, to determine which directories to use for importing modules. If an adversary is able to + control the value of PYTHONPATH, they can point it to an attacker-controlled directory and hijack + imported packages, achieving user-level persistence across future Python invocations and new shell + sessions. If confirmed malicious, this could result in arbitrary code execution every time Python + is invoked by the affected user. +data_source: + - Sysmon EventID 1 + - Sysmon EventID 13 +search: |- + `sysmon` EventID IN (1,13) AND (CommandLine="* install *" OR (TargetObject="*PYTHONPATH" AND action="modified")) + | bin _time span=5m + | stats values(parent_process_id) as parent_process_id, values(TargetObject) as TargetObject, values(registry_value_data) as registry_value_data, values(CommandLine) as CommandLine, values(parent_process) as parent_process, dc(EventID) as dc_event_id count by _time, host, source, process_id + | search dc_event_id>1 + | `python_pythonpath_modification_during_package_installation_filter` +how_to_implement: |- + This detection requires Sysmon event logs. Configure your environment to ingest Sysmon process creation (EventID 1) + and registry modification (EventID 13) events, ensuring that registry modification events are collected for the + PYTHONPATH environment variable(\Environment\PYTHONPATH). Ingest the data via the appropriate Splunk Technology Add-on + and normalize field names using the Splunk Common Information Model (CIM). +known_false_positives: |- + Developers and legitimate installers may modify PYTHONPATH as part of normal environment configuration. + Investigate the new value and parent process to determine legitimacy. +references: + - https://blog.talosintelligence.com/the-serpents-tongue-luring-the-python-out-of-its-den/ +drilldown_searches: + - name: View the detection results for - "$host$" + search: '%original_detection_search% | search host = "$host$"' + earliest_offset: $info_min_time$ + latest_offset: $info_max_time$ + - name: View risk events for the last 7 days for - "$host$" + search: '| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$host$") | stats count min(_time) as firstTime max(_time) as lastTime values(search_name) as "Search Name" values(risk_message) as "Risk Message" values(analyticstories) as "Analytic Stories" values(annotations._all) as "Annotations" values(annotations.mitre_attack.mitre_tactic) as "ATT&CK Tactics" by normalized_risk_object | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`' + earliest_offset: 7d + latest_offset: "0" +finding: + title: The PYTHONPATH environment variable was modified on $host$ during package installation + entity: + field: host + type: system + score: 40 +analytic_story: + - Malicious Python Package Installation + - Compromised Windows Host + - Windows Persistence Techniques + - Suspicious Windows Registry Activities + - Windows Registry Abuse +asset_type: Endpoint +mitre_attack_id: + - T1574.007 + - T1195.002 +product: + - Splunk Enterprise + - Splunk Enterprise Security + - Splunk Cloud +category: endpoint +security_domain: endpoint +tests: + - name: True Positive Test + attack_data: + - data: https://raw.githubusercontent.com/splunk/attack_data/refs/heads/master/datasets/attack_techniques/T1574.007/python_pythonpath_modification/python_pythonpath_modification.log + source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational + sourcetype: XmlWinEventLog + test_type: unit diff --git a/detections/endpoint/python_site_hooks_creation_during_package_installation.yml b/detections/endpoint/python_site_hooks_creation_during_package_installation.yml new file mode 100644 index 0000000000..b8b8bdd4c4 --- /dev/null +++ b/detections/endpoint/python_site_hooks_creation_during_package_installation.yml @@ -0,0 +1,71 @@ +name: Python Site Hooks Creation during Package Installation +id: efaf40f5-779f-4b48-a941-b7d1a7c931ed +version: 1 +creation_date: '2026-07-23' +modification_date: '2026-07-23' +author: Onur Mustafa Erdogan, Splunk +status: production +type: TTP +description: |- + The following analytic detects the creation of a Python site hook file (`sitecustomize.py` or `usercustomize.py`) + within a `site-packages`/`dist-packages` directory in conjunction with a package installation process. Python's + `site` module loads these hooks from directories on `sys.path` before Python is executed. If an adversary manipulates + or plants one of these files, they can hijack the Python environment and execute their payload with every Python + invocation, achieving persistence on the victim endpoint. The VIPERTUNNEL backdoor was reported to abuse site hooks + in order to import and trigger DLL execution. If confirmed malicious, this could result in arbitrary code execution + every time Python is invoked on the compromised host. +data_source: + - Sysmon EventID 1 + - Sysmon EventID 11 +search: |- + `sysmon` EventID IN (1,11) AND (CommandLine="* install *" OR (TargetFilename="*-packages\*" AND action="created" AND (TargetFilename="*sitecustomize.py" OR TargetFilename="*usercustomize.py"))) + | bin _time span=5m + | stats values(parent_process_id) as val_parent_process_id, values(TargetFilename) as val_target_filename, values(CommandLine) as val_cmd_line, values(parent_process) as val_parent_process, dc(EventID) as dc_event_id count by _time, host, source, process_id + | search dc_event_id>1 + | `python_site_hooks_creation_during_package_installation_filter` +how_to_implement: |- + This detection requires Sysmon event logs. Configure your environment to ingest Sysmon process creation (EventID 1) + and file creation (EventID 11) events, ensuring that file creation events are collected for files with the .py + extension. Ingest the data via the appropriate Splunk Technology Add-on and normalize field names using the + Splunk Common Information Model (CIM). +known_false_positives: |- + Some legitimate tooling and environment managers create or modify `sitecustomize.py`/`usercustomize.py` + as part of normal setup. Investigate the file contents and parent process to determine legitimacy. +references: + - https://blog.talosintelligence.com/the-serpents-tongue-luring-the-python-out-of-its-den/ +drilldown_searches: + - name: View the detection results for - "$host$" + search: '%original_detection_search% | search host = "$host$"' + earliest_offset: $info_min_time$ + latest_offset: $info_max_time$ + - name: View risk events for the last 7 days for - "$host$" + search: '| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$host$") | stats count min(_time) as firstTime max(_time) as lastTime values(search_name) as "Search Name" values(risk_message) as "Risk Message" values(analyticstories) as "Analytic Stories" values(annotations._all) as "Annotations" values(annotations.mitre_attack.mitre_tactic) as "ATT&CK Tactics" by normalized_risk_object | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`' + earliest_offset: 7d + latest_offset: "0" +finding: + title: A Python site hook file was created on $host$ during package installation + entity: + field: host + type: system + score: 40 +analytic_story: + - Malicious Python Package Installation + - Compromised Windows Host + - Windows Persistence Techniques +asset_type: Endpoint +mitre_attack_id: + - T1546 + - T1195.002 +product: + - Splunk Enterprise + - Splunk Enterprise Security + - Splunk Cloud +category: endpoint +security_domain: endpoint +tests: + - name: True Positive Test + attack_data: + - data: https://raw.githubusercontent.com/splunk/attack_data/refs/heads/master/datasets/attack_techniques/T1546/python_site_hooks_creation/python_site_hooks_creation.log + source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational + sourcetype: XmlWinEventLog + test_type: unit diff --git a/stories/malicious_python_package_installation.yml b/stories/malicious_python_package_installation.yml new file mode 100644 index 0000000000..b05343eef8 --- /dev/null +++ b/stories/malicious_python_package_installation.yml @@ -0,0 +1,36 @@ +name: Malicious Python Package Installation +id: 12e51c50-6b66-4ce7-83b8-95125ffd31e9 +version: 1 +creation_date: '2026-07-23' +modification_date: '2026-07-23' +author: Onur Mustafa Erdogan, Splunk +status: production +description: |- + This analytic story provides detection coverage for abuse of the Python package installation lifecycle, + including install-time code execution, persistence via `.pth` path configuration files, Python site hooks, + and PYTHONPATH environment variable manipulation. +narrative: |- + Python's popularity, readable syntax, and extensive third-party library ecosystem make it an attractive target + for threat actors seeking to compromise developer devices and infrastructure. Malicious packages and supply-chain + attacks exploit the trust built into Python's packaging ecosystem to execute payloads at the moment of installation, + without any direct interaction from the victim. Adversaries abuse several native Python features to achieve this. + `setup.py` build scripts can leverage `distutils`/`setuptools` command classes to execute arbitrary code, including + network beacons, during package installation. Path configuration files (`.pth`) placed in `site-packages`/`dist-packages` + are executed on every subsequent Python invocation, providing persistence; this technique was used by the threat actor + group TeamPCP during the supply-chain compromise of the `litellm` package. Python's `site` module also loads `sitecustomize.py` + and `usercustomize.py` hook files from directories on `sys.path`, which adversaries can plant or manipulate to hijack + the Python environment and achieve persistence, as seen with the VIPERTUNNEL backdoor. Finally, adversaries who can + modify a user's `PYTHONPATH` environment variable can redirect module imports to attacker-controlled directories,achieving + user-level persistence across new shell sessions. This story detects these behaviors by correlating process creation, + file creation, and registry modification telemetry around Python package installation activity. +references: + - https://blog.talosintelligence.com/the-serpents-tongue-luring-the-python-out-of-its-den/ +category: + - Adversary Tactics +usecase: Advanced Threat Detection +threat_group: + - TeamPCP +product: + - Splunk Enterprise + - Splunk Enterprise Security + - Splunk Cloud