Exfiltration (TA0010)(external, opens in a new tab or window)
text code block:event.category : "process" and event.type : "start" and process.name : ( Cyberduck or S3Browser.exe or aws-shell or cyberduck or duck or duck.exe or goofys or juicefs or mc or mc.exe or rclone or rclone.exe or s3browser-con.exe or s3browser.exe or s3cmd or s3cmd.exe or s3fs or s5cmd or s5cmd.exe or *bucketexplorer* or *cloudberry* or *s3browser* ) and not ( process.name : (mc or mc.exe) and not process.args : (admin or alias or cat or cp or du or find or get or ls or mb or mirror or mv or pipe or put or rb or rm or share or stat or tree) ) and not process.executable : (/opt/Elastic/Agent/* or /usr/lib/systemd/*) and not process.args : (--help or --version or -h or selfupdate or version) and ( process.parent.name : ( bun or bun.exe or cscript.exe or deno or deno.exe or mshta.exe or node or node.exe or nodejs or perl* or php* or python* or ruby* or wscript.exe ) or ( process.parent.name : (bash or bash.exe or cmd.exe or dash or fish or ksh or powershell.exe or pwsh or pwsh.exe or sh or zsh) and process.parent.args : ("-Command" or "-EncodedCommand" or "-enc" or "-e" or "-c" or "-ilc" or "-lc" or "/c") ) or process.executable : ( *\\Users\\*\\AppData\\Local\\Temp\\* or *\\Users\\Public\\* or *\\Windows\\Temp\\* or /Users/Shared/* or /dev/shm/* or /private/tmp/* or /tmp/* or /var/tmp/* ) or process.parent.executable : ( *\\Users\\*\\AppData\\Local\\Temp\\* or *\\Users\\Public\\* or *\\Windows\\Temp\\* or /Users/Shared/* or /dev/shm/* or /private/tmp/* or /tmp/* or /var/tmp/* ) )
Install detection rules in Elastic Security
Detect Potential Third-Party Cloud Storage Client Execution in the Elastic Security detection engine by installing this rule into your Elastic Stack.
To setup this rule, check out the installation guide for Prebuilt Security Detection Rules(external, opens in a new tab or window).