Created
March 31, 2026 01:54
-
-
Save peasead/8b9b6a2039f4c00f4ca0bbe7f1dbd172 to your computer and use it in GitHub Desktop.
Detections for the TeamPCP_Shai Hulud (LiteLLM_Trivy) threat actors_intrusion set.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| Elastic Tested Detections — TeamPCP / Shai Hulud (LiteLLM · Trivy) | |
| Endpoint: | |
| :new: Suspicious Python Shell Command Execution https://github.com/elastic/detection-rules/blob/c932ececd9c3b1257fc0350ec2dc13a1af0d6f88/rules/cross-platform/execution_suspicious_python_command_execution.toml | |
| :new: Potential Credential Discovery via Recursive Grep https://github.com/elastic/detection-rules/blob/main/rules/cross-platform/credential_access_grep_recursive_credential_discovery.toml | |
| Potential Data Exfiltration Through Curl https://github.com/elastic/detection-rules/blob/c932ececd9c3b1257fc0350ec2dc13a1af0d6f88/rules/cross-platform/exfiltration_potential_curl_data_exfiltration.toml | |
| :new: Kubectl Secrets Enumeration Across All Namespaces https://github.com/elastic/detection-rules/blob/c932ececd9c3b1257fc0350ec2dc13a1af0d6f88/rules/cross-platform/discovery_kubectl_secrets_all_namespaces.toml#L28 | |
| :new: Data Encrypted via OpenSSL Utility https://github.com/elastic/detection-rules/blob/c932ececd9c3b1257fc0350ec2dc13a1af0d6f88/rules/cross-platform/defense_evasion_data_encrypted_via_openssl.toml | |
| Python Path File (pth) Creation https://github.com/elastic/detection-rules/blob/4fb6bd2bdb92b91ca42f5d667c9460b85ea2fb52/rules/linux/persistence_pth_file_creation.toml | |
| Shell Command Discovery Execution via Untrusted Binary - https://github.com/elastic/protections-artifacts/blob/331b0c762ef5293cea812a9b676e84527fbe5f73/behavior/rules/macos/execution_shell_command_discovery_execution_via_untrusted_binary.toml#L8 | |
| Potential Data Exfiltration via Curl - https://github.com/elastic/protections-artifacts/blob/331b0c762ef5293cea812a9b676e84527fbe5f73/behavior/rules/macos/exfiltration_potential_data_exfiltration_via_curl.toml#L10 | |
| Suspicious Python Command Execution - https://github.com/elastic/protections-artifacts/blob/331b0c762ef5293cea812a9b676e84527fbe5f73/behavior/rules/linux/execution_suspicious_python_command_execution.toml#L9 | |
| Cloud_defend: | |
| File Execution Permission Modification Detected via Defend for Containers https://github.com/elastic/detection-rules/blob/c932ececd9c3b1257fc0350ec2dc13a1af0d6f88/rules/integrations/cloud_defend/execution_suspicious_file_made_executable_via_chmod_inside_a_container.toml#L21 | |
| Suspicious Echo or Printf Execution Detected via Defend for Containers https://github.com/elastic/detection-rules/blob/main/rules/integrations/cloud_defend/persistence_suspicious_echo_or_printf_execution.toml | |
| Chroot Execution Detected via Defend for Containers https://github.com/elastic/detection-rules/blob/c932ececd9c3b1257fc0350ec2dc13a1af0d6f88/rules/integrations/cloud_defend/privilege_escalation_chroot_execution_detected_inside_container.toml | |
| Kubernetes: | |
| Kubernetes Privileged Pod Created https://github.com/elastic/detection-rules/blob/main/rules/integrations/kubernetes/privilege_escalation_privileged_pod_created.toml | |
| Kubernetes Pod Created With HostNetwork https://github.com/elastic/detection-rules/blob/main/rules/integrations/kubernetes/privilege_escalation_pod_created_with_hostnetwork.toml | |
| Kubernetes Pod Created with a Sensitive hostPath Volume https://github.com/elastic/detection-rules/blob/main/rules/integrations/kubernetes/privilege_escalation_pod_created_with_sensitive_hostpath_volume.toml | |
| Multiple Cloud Secrets Accessed by Source Address https://github.com/elastic/detection-rules/blob/c4828769743cd64818ce524657a2c6bda0ab2adf/rules/cross-platform/credential_access_multi_could_secrets_via_api.toml | |
| :new: Kubernetes Secret Access via Unusual User Agent https://github.com/elastic/detection-rules/blob/c932ececd9c3b1257fc0350ec2dc13a1af0d6f88/rules/integrations/kubernetes/credential_access_get_secrets_access.toml#L17 |
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment