~1m13:39SYSMON FOR LINUX?? - Learn to Install Sysmon For Linux
Jan 5, 2022
Read: ~3m · You save: 11 min
SYSMON FOR LINUX: Installation and Real-time Monitoring
Sysmon, a system monitoring tool previously exclusive to Windows, has been extended to the Linux operating system. This development allows for the collection of detailed system events in real-time, mirroring the capabilities previously available for Windows environments.
Key Benefits and Event Types
Sysmon for Linux leverages Extended Berkeley Packet Filter (eBPF) technology, which operates at a low level within the kernel. This enables real-time event logging, a distinction from tools like OSQuery that rely on scheduled jobs. eBPF's low-level access permits the logging of a variety of system activities.
Currently available event types include:
- Process creations
- Network connections
- Process terminations
- Raw access reads
- Process access
- File creation
- File deletions
A notable absence in the current release is DNS query logging, though this is anticipated to be added in future updates as the project is under active community development.
System Requirements and Installation
To install Sysmon for Linux, the following are required:
- A Linux-based operating system.
- The ability to compile eBPF.
- A Sysmon configuration file (
config.xml) to define which events to collect.
The installation process involves compiling dependencies, installing the Sysmon package, and configuring the service with a config.xml file.
Installation Steps (Ubuntu 20.04 Example)
The following steps outline the installation process on an Ubuntu 20.04 system. Commands for other Linux distributions are available in the project's documentation.
- Install and compile dependencies:
sudo apt update sudo apt install build-essential libelf-dev linux-headers-$(uname -r) - Download and install the Sysmon package:
wget https://packages.microsoft.com/config/ubuntu/$(lsb_release -rs)/packages-microsoft-prod.deb -O packages-microsoft-prod.deb sudo dpkg -i packages-microsoft-prod.deb rm packages-microsoft-prod.deb sudo apt update sudo apt install sysmonforlinux - Configure Sysmon:
Create a
config.xmlfile. A sample configuration file, which specifies the events to be collected, is available from community resources. This file should be placed in a suitable directory. - Install and start the Sysmon service:
To verify the service status:sudo sysmon --accept-ula --config config.xmlsystemctl status sysmon
Log Output and Analysis
On Ubuntu systems, Sysmon logs are written to /var/log/syslog. On CentOS, logs are typically outputted to /var/log/messages. The default log format is XML, which can be difficult to read directly.
Example Log Analysis
File Creation:
When a file is created, for instance, malware.txt in the /opt/malware directory using the nano editor, Sysmon logs this event. The log entry details the process (nano), the file created (malware.txt), and the user who performed the action.
Network Connections:
Initiating a wget command to download a file from a specific IPv6 address generates a network connection event. The log captures the wget binary, command-line arguments, the destination IP address, the protocol used (TCP), and the user who executed the command.
File Deletion:
Deleting a file using the rm command is also logged, indicating the process and the file that was removed.
Limitations and Future Developments
A current limitation is the absence of JSON output support, which is a requested feature. The XML format requires parsing for analysis by security tools like Wazuh. Future developments are expected to include decoders to enable the parsing of Sysmon for Linux XML logs for integration with platforms like Elasticsearch and Kibana.
Introduction to Sysmon for Linux
Introduction to Sysmon for Linux, highlighting its real-time monitoring capabilities, similar to Sysmon for Windows, and its reliance on eBPF for kernel-level access.
- Sysmon for Linux is now available, extending real-time monitoring to Linux systems.
- It provides richer information than standard logging, akin to Sysmon for Windows.
- Leverages eBPF for low-level kernel access, enabling real-time event collection.
- Key events logged include process creations, network connections, process terminations, raw access reads, process access, file creation, and file deletions.