Deployable detection rules
1 vendor-native detections · ready to paste into your SIEM · cross-linked to ATT&CK
◈
Detections
1 shown of 1Linux Audio Recording Activity Detected
This rule monitors for the usage of the most common audio recording utilities on unix systems by an uncommon process parent.
Adversaries may collect audio data from users or systems for a variety of reasons including espionage, credential theft, or reconnaissance.
Show query
event.category:process and host.os.type:"linux" and event.type:"start" and event.action:("exec" or "exec_event" or "start") and (
process.name:("arecord" or "parec" or "pw-record" or "ecasound") or
(process.name:"pw-cat" and process.args:"-r") or
(process.name:"ffmpeg" and process.args:"-i")
) and
not process.args:("-h" or "--help" or "--version")
Showing 1-1 of 1