Skip to content

Instantly share code, notes, and snippets.

@peasead
Created March 31, 2026 01:54
Show Gist options
  • Select an option

  • Save peasead/8b9b6a2039f4c00f4ca0bbe7f1dbd172 to your computer and use it in GitHub Desktop.

Select an option

Save peasead/8b9b6a2039f4c00f4ca0bbe7f1dbd172 to your computer and use it in GitHub Desktop.
Detections for the TeamPCP_Shai Hulud (LiteLLM_Trivy) threat actors_intrusion set.
Elastic Tested Detections — TeamPCP / Shai Hulud (LiteLLM · Trivy)
Endpoint:
:new: Suspicious Python Shell Command Execution https://github.com/elastic/detection-rules/blob/c932ececd9c3b1257fc0350ec2dc13a1af0d6f88/rules/cross-platform/execution_suspicious_python_command_execution.toml
:new: Potential Credential Discovery via Recursive Grep https://github.com/elastic/detection-rules/blob/main/rules/cross-platform/credential_access_grep_recursive_credential_discovery.toml
Potential Data Exfiltration Through Curl https://github.com/elastic/detection-rules/blob/c932ececd9c3b1257fc0350ec2dc13a1af0d6f88/rules/cross-platform/exfiltration_potential_curl_data_exfiltration.toml
:new: Kubectl Secrets Enumeration Across All Namespaces https://github.com/elastic/detection-rules/blob/c932ececd9c3b1257fc0350ec2dc13a1af0d6f88/rules/cross-platform/discovery_kubectl_secrets_all_namespaces.toml#L28
:new: Data Encrypted via OpenSSL Utility https://github.com/elastic/detection-rules/blob/c932ececd9c3b1257fc0350ec2dc13a1af0d6f88/rules/cross-platform/defense_evasion_data_encrypted_via_openssl.toml
Python Path File (pth) Creation https://github.com/elastic/detection-rules/blob/4fb6bd2bdb92b91ca42f5d667c9460b85ea2fb52/rules/linux/persistence_pth_file_creation.toml
Shell Command Discovery Execution via Untrusted Binary - https://github.com/elastic/protections-artifacts/blob/331b0c762ef5293cea812a9b676e84527fbe5f73/behavior/rules/macos/execution_shell_command_discovery_execution_via_untrusted_binary.toml#L8
Potential Data Exfiltration via Curl - https://github.com/elastic/protections-artifacts/blob/331b0c762ef5293cea812a9b676e84527fbe5f73/behavior/rules/macos/exfiltration_potential_data_exfiltration_via_curl.toml#L10
Suspicious Python Command Execution - https://github.com/elastic/protections-artifacts/blob/331b0c762ef5293cea812a9b676e84527fbe5f73/behavior/rules/linux/execution_suspicious_python_command_execution.toml#L9
Cloud_defend:
File Execution Permission Modification Detected via Defend for Containers https://github.com/elastic/detection-rules/blob/c932ececd9c3b1257fc0350ec2dc13a1af0d6f88/rules/integrations/cloud_defend/execution_suspicious_file_made_executable_via_chmod_inside_a_container.toml#L21
Suspicious Echo or Printf Execution Detected via Defend for Containers https://github.com/elastic/detection-rules/blob/main/rules/integrations/cloud_defend/persistence_suspicious_echo_or_printf_execution.toml
Chroot Execution Detected via Defend for Containers https://github.com/elastic/detection-rules/blob/c932ececd9c3b1257fc0350ec2dc13a1af0d6f88/rules/integrations/cloud_defend/privilege_escalation_chroot_execution_detected_inside_container.toml
Kubernetes:
Kubernetes Privileged Pod Created https://github.com/elastic/detection-rules/blob/main/rules/integrations/kubernetes/privilege_escalation_privileged_pod_created.toml
Kubernetes Pod Created With HostNetwork https://github.com/elastic/detection-rules/blob/main/rules/integrations/kubernetes/privilege_escalation_pod_created_with_hostnetwork.toml
Kubernetes Pod Created with a Sensitive hostPath Volume https://github.com/elastic/detection-rules/blob/main/rules/integrations/kubernetes/privilege_escalation_pod_created_with_sensitive_hostpath_volume.toml
Multiple Cloud Secrets Accessed by Source Address https://github.com/elastic/detection-rules/blob/c4828769743cd64818ce524657a2c6bda0ab2adf/rules/cross-platform/credential_access_multi_could_secrets_via_api.toml
:new: Kubernetes Secret Access via Unusual User Agent https://github.com/elastic/detection-rules/blob/c932ececd9c3b1257fc0350ec2dc13a1af0d6f88/rules/integrations/kubernetes/credential_access_get_secrets_access.toml#L17
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment