This website uses cookies to ensure you get the best experience.
Got it!
Register
|
Login
Menu
Home
Sigma Rules
Splunk Rules
Explore Rules
Analytic Stories
MITRE ATT&CK
Overview
Matrix
Techniques
Groups
Software
Campaigns
Search
About
Nohup Execution
Original Source:
[Sigma source]
Title:
Nohup Execution
Status:
test
Description:
Detects usage of nohup which could be leveraged by an attacker to keep a process running or break out from restricted environments
References:
-https://gtfobins.github.io/gtfobins/nohup/
-https://en.wikipedia.org/wiki/Nohup
-https://www.computerhope.com/unix/unohup.htm
Author:
Christopher Peacock @SecurePeacock, SCYTHE @scythe_io
Date:
2022-06-06
modified:
None
Tags:
-'attack.execution'
-'attack.t1059.004'
Logsource:
product: linux
category: process_creation
Detection:
selection:
Image|endswith
:
'/nohup'
condition
:
selection
Falsepositives:
-Administrators or installed processes that leverage nohup
Level:
medium