- Joined
- Jan 19, 2023
- Messages
- 13
- Reaction score
- 3
Hello,
We have recently received the below alert from our SIEM providers. It mentions that tcpdump was run on the 3CX system with root privileges. Is this some kind of automated scanning by the system or triggered by any other activity in the admin console?
> Incident Description: This Query is designed to determine a Process Injection on Linux System by detecting an event where command line contains any of tcpdump or tshark, This is an open-source sniffing tool that is used for packet capture and analysis. tcpdump runs using a command line interface. tcpdump has also been custom-designed for packet capturing as it does not have a GUI that enables the analysis and display of data.
> Alert Time: 12/01/2024 13:28:21
Event Details:
> Event ID: 44251582
> Event Name: Privilege Escalation Succeeded
> Event Description: Privilege escalation was successful
> Event Count: 1
User/Account Details
> User Name: root
Process Details:
> Command Line: /usr/sbin/tcpdump -D
We have recently received the below alert from our SIEM providers. It mentions that tcpdump was run on the 3CX system with root privileges. Is this some kind of automated scanning by the system or triggered by any other activity in the admin console?
> Incident Description: This Query is designed to determine a Process Injection on Linux System by detecting an event where command line contains any of tcpdump or tshark, This is an open-source sniffing tool that is used for packet capture and analysis. tcpdump runs using a command line interface. tcpdump has also been custom-designed for packet capturing as it does not have a GUI that enables the analysis and display of data.
> Alert Time: 12/01/2024 13:28:21
Event Details:
> Event ID: 44251582
> Event Name: Privilege Escalation Succeeded
> Event Description: Privilege escalation was successful
> Event Count: 1
User/Account Details
> User Name: root
Process Details:
> Command Line: /usr/sbin/tcpdump -D