Detection of Suspicious Shared Object Creation on Linux
This brief addresses the detection of unauthorized shared object (.so) file creation in sensitive system directories, a technique commonly used by attackers for persistence and code injection on Linux systems.
Monitoring for the creation of shared object files is critical for identifying persistence mechanisms on Linux endpoints. Attackers often compile malicious code into dynamically linked libraries (.so files) and place them in system directories to achieve execution, inject functionality into legitimate processes, or bypass security controls at runtime. While legitimate system management tasks, such as software updates or application installations, frequently involve the creation of these files, malicious activity is often characterized by the use of previously unknown or uncommon processes performing these actions outside of standard package management workflows. By tracking file creation events in sensitive library paths, security teams can identify potentially unauthorized library loading or backdooring of applications that would otherwise evade standard process-based detection.
Impact
Successful exploitation allows for stealthy persistence, privilege escalation via code injection, and potential bypass of security monitoring. Compromised systems may experience reduced integrity and confidentiality as malicious libraries interact with system-level services and user applications. If left undetected, this allows attackers to maintain long-term access, execute unauthorized code within the context of trusted processes, and exfiltrate sensitive data.
Recommendation
Prioritize the investigation of file creation events in sensitive directories triggered by unknown processes.
- Deploy the provided Sigma rule to detect the creation of shared object files in system-wide library paths.
- Tune existing detection logic by creating allowlists for known-good administrative processes and package managers documented in the Sigma filter.
- Utilize OSQuery to perform ad-hoc investigation of suspect shared objects, checking for file ownership, modification times, and associated process trees.
- Investigate the parent process of any suspicious .so creation to determine the execution chain and evaluate if the binary originates from a trusted source.
Immediate actions
Deploy the Sigma rule to the SIEM
Threat Hunt
Search for recently created .so files in sensitive paths not associated with known package managers
Data: File system audit logs
Mitigations
Implement strict file integrity monitoring (FIM) on /usr/lib and /lib directories
Persistence via file modification
Detection coverage 1
Detect Suspicious Shared Object Creation
mediumDetects the creation of shared object files in critical system directories by unknown processes, which may indicate persistence or unauthorized code injection.
Detection queries are available on the platform. Get full rules →