Skip to content

add send SMS on Android#818

Merged
mr-tz merged 1 commit intomasterfrom
rules52-34
Oct 9, 2023
Merged

add send SMS on Android#818
mr-tz merged 1 commit intomasterfrom
rules52-34

Conversation

@mr-tz
Copy link
Collaborator

@mr-tz mr-tz commented Aug 27, 2023

First rule for Android (native code called via JNI), here from a private 64-bit .so file. Very similar code is also referenced in https://stackoverflow.com/questions/30175062/jni-callvoidmethod-leads-to-fatal-signal-6-and-invalid-indirect-reference.

Question: do we want to mix mobile with desktop for namespaces and ATT&CK?

Comment on lines +8 to +9
# att&ck:
# - Mobile::SMS Control [T1582]
Copy link
Collaborator Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

we currently only lint for Enterprise techniques, not https://attack.mitre.org/techniques/mobile/

Copy link
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

seems reasonable to add, assuming it's low effort and maintenance. we could also wait until someone wants to use this and/or we have more substantial coverage.

- os: android
# ... = (*env)->FindClass(env, "android/telephony/SmsManager");
- string: "android/telephony/SmsManager"
- optional:
Copy link
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

eventually we'll probably want to factor this out, but let's wait until it's used in a few places first.

Copy link
Collaborator Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

yeah, probably a good idea to write a few dozen rules and talk to potential users first

Comment on lines +8 to +9
# att&ck:
# - Mobile::SMS Control [T1582]
Copy link
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

seems reasonable to add, assuming it's low effort and maintenance. we could also wait until someone wants to use this and/or we have more substantial coverage.

@mr-tz mr-tz merged commit fcfb7ef into master Oct 9, 2023
@mr-tz mr-tz deleted the rules52-34 branch October 9, 2023 16:26
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants