False positive QRadar detection

rish420

Customer
Joined
Jan 19, 2023
Messages
13
Reaction score
3
Hello,

We have recently received the below alert from our SIEM providers. It mentions that tcpdump was run on the 3CX system with root privileges. Is this some kind of automated scanning by the system or triggered by any other activity in the admin console?

> Incident Description: This Query is designed to determine a Process Injection on Linux System by detecting an event where command line contains any of tcpdump or tshark, This is an open-source sniffing tool that is used for packet capture and analysis. tcpdump runs using a command line interface. tcpdump has also been custom-designed for packet capturing as it does not have a GUI that enables the analysis and display of data.
> Alert Time: 12/01/2024 13:28:21

Event Details:
> Event ID: 44251582
> Event Name: Privilege Escalation Succeeded
> Event Description: Privilege escalation was successful
> Event Count: 1

User/Account Details
> User Name: root

Process Details:
> Command Line: /usr/sbin/tcpdump -D
 
Hi,

Did you run a network capture from the Management Console?

That would fit the description of the alert. I assume your SIEM provides more details about the detection which you can review to confirm.
 
No, we did not initiate a network capture from the management console. Would there be any other actions that would trigger this action?
 
That specific command just lists the interfaces that tcpdump can capture traffic on. It is triggered when you just open the logs page in the Management Console (without starting a capture).

Now as mentioned, we can’t know the details of your SIEM detection, nor the setup of your self hosted server etc. What I can say is that legitimate use of it by the pbx might trigger such an alert.

You can check your server logs to confirm this. For example in /var/log/auth.log you may see an entry matching that command being ran by the pbx (phonesystem user) at the time of the detection.
 
  • Like
Reactions: rish420
That specific command just lists the interfaces that tcpdump can capture traffic on. It is triggered when you just open the logs page in the Management Console (without starting a capture).

Now as mentioned, we can’t know the details of your SIEM detection, nor the setup of your self hosted server etc. What I can say is that legitimate use of it by the pbx might trigger in such an alert.
Thank you for this. It's put my mind at ease. I can confirm that we did indeed open the logs page in the Management console.
 
You’re welcome, glad I could help. Have a nice weekend.
 

Forum statistics

Threads
111,819
Messages
589,168
Members
164,642
Latest member
davids86