~1m13:39
Taylor Walton

SYSMON FOR LINUX?? - Learn to Install Sysmon For Linux

Jan 5, 2022

Read: ~3m · You save: 11 min

SYSMON FOR LINUX: Installation and Real-time Monitoring

Sysmon, a system monitoring tool previously exclusive to Windows, has been extended to the Linux operating system. This development allows for the collection of detailed system events in real-time, mirroring the capabilities previously available for Windows environments.

Key Benefits and Event Types

Sysmon for Linux leverages Extended Berkeley Packet Filter (eBPF) technology, which operates at a low level within the kernel. This enables real-time event logging, a distinction from tools like OSQuery that rely on scheduled jobs. eBPF's low-level access permits the logging of a variety of system activities.

Currently available event types include:

  • Process creations
  • Network connections
  • Process terminations
  • Raw access reads
  • Process access
  • File creation
  • File deletions

A notable absence in the current release is DNS query logging, though this is anticipated to be added in future updates as the project is under active community development.

System Requirements and Installation

To install Sysmon for Linux, the following are required:

  • A Linux-based operating system.
  • The ability to compile eBPF.
  • A Sysmon configuration file (config.xml) to define which events to collect.

The installation process involves compiling dependencies, installing the Sysmon package, and configuring the service with a config.xml file.

Installation Steps (Ubuntu 20.04 Example)

The following steps outline the installation process on an Ubuntu 20.04 system. Commands for other Linux distributions are available in the project's documentation.

  1. Install and compile dependencies:
    sudo apt update
    sudo apt install build-essential libelf-dev linux-headers-$(uname -r)
    
  2. Download and install the Sysmon package:
    wget https://packages.microsoft.com/config/ubuntu/$(lsb_release -rs)/packages-microsoft-prod.deb -O packages-microsoft-prod.deb
    sudo dpkg -i packages-microsoft-prod.deb
    rm packages-microsoft-prod.deb
    sudo apt update
    sudo apt install sysmonforlinux
    
  3. Configure Sysmon: Create a config.xml file. A sample configuration file, which specifies the events to be collected, is available from community resources. This file should be placed in a suitable directory.
  4. Install and start the Sysmon service:
    sudo sysmon --accept-ula --config config.xml
    
    To verify the service status:
    systemctl status sysmon
    

Log Output and Analysis

On Ubuntu systems, Sysmon logs are written to /var/log/syslog. On CentOS, logs are typically outputted to /var/log/messages. The default log format is XML, which can be difficult to read directly.

Example Log Analysis

File Creation: When a file is created, for instance, malware.txt in the /opt/malware directory using the nano editor, Sysmon logs this event. The log entry details the process (nano), the file created (malware.txt), and the user who performed the action.

Network Connections: Initiating a wget command to download a file from a specific IPv6 address generates a network connection event. The log captures the wget binary, command-line arguments, the destination IP address, the protocol used (TCP), and the user who executed the command.

File Deletion: Deleting a file using the rm command is also logged, indicating the process and the file that was removed.

Limitations and Future Developments

A current limitation is the absence of JSON output support, which is a requested feature. The XML format requires parsing for analysis by security tools like Wazuh. Future developments are expected to include decoders to enable the parsing of Sysmon for Linux XML logs for integration with platforms like Elasticsearch and Kibana.

Introduction to Sysmon for Linux

Introduction to Sysmon for Linux, highlighting its real-time monitoring capabilities, similar to Sysmon for Windows, and its reliance on eBPF for kernel-level access.

  • Sysmon for Linux is now available, extending real-time monitoring to Linux systems.
  • It provides richer information than standard logging, akin to Sysmon for Windows.
  • Leverages eBPF for low-level kernel access, enabling real-time event collection.
  • Key events logged include process creations, network connections, process terminations, raw access reads, process access, file creation, and file deletions.
This analysis saves 11 min of your time (13:39 → ~3m)