← Back to Explore
sigmamediumHunting
Terminate Linux Process Via Kill
Detects usage of command line tools such as "kill", "pkill" or "killall" to terminate or signal a running process.
MITRE ATT&CK
Detection Query
selection:
Image|endswith:
- /kill
- /killall
- /pkill
- /xkill
condition: selection
Author
Tuan Le (NCSGroup)
Created
2023-03-16
Data Sources
linuxProcess Creation Events
Platforms
linux
References
Tags
attack.defense-impairmentattack.t1685detection.threat-hunting
Raw Content
title: Terminate Linux Process Via Kill
id: 64c41342-6b27-523b-5d3f-c265f3efcdb3
status: test
description: Detects usage of command line tools such as "kill", "pkill" or "killall" to terminate or signal a running process.
references:
- https://www.trendmicro.com/en_us/research/23/c/iron-tiger-sysupdate-adds-linux-targeting.html
- https://www.cyberciti.biz/faq/how-force-kill-process-linux/
- https://www.geeksforgeeks.org/how-to-kill-processes-on-the-linux-desktop-with-xkill/
author: Tuan Le (NCSGroup)
date: 2023-03-16
modified: 2024-12-12
tags:
- attack.defense-impairment
- attack.t1685
- detection.threat-hunting
logsource:
product: linux
category: process_creation
detection:
selection:
Image|endswith:
- '/kill'
- '/killall'
- '/pkill'
- '/xkill'
condition: selection
falsepositives:
- Unknown
level: medium