Linux Suspicious Redis Activity: endpointEndpointNoneversion:1
The following analytic detects Redis processes spawning a system shell command. This can indicate exploitation activity of a redis server to gain code execution.
Linux Shell History Access Via Command Line Utility: endpointEndpointNoneversion:1
The following analytic detects attempts to read shell history files (bash, zsh, fish, etc.).
A history file is a log file that records all the commands executed in a shell on a Linux or Unix-based operating system.
A malicious actor who gains access to a user's shell history file can potentially obtain sensitive information and use it to compromise the user's system and data.
Suspicious Linux Discovery Commands: endpointEndpointNoneversion:11
The following analytic detects the execution of suspicious bash commands commonly used in scripts like AutoSUID, LinEnum, and LinPeas for system discovery on a Linux host. It leverages Endpoint Detection and Response (EDR) data, specifically looking for a high number of distinct commands executed within a short time frame. This activity is significant as it often precedes privilege escalation or other malicious actions. If confirmed malicious, an attacker could gain detailed system information, identify vulnerabilities, and potentially escalate privileges, posing a severe threat to the environment.
Linux Possible Nimbuspwn Privilege Escalation: endpointEndpointNoneversion:1
The following analytic detects directory traversal attempts associated with Nimbuspwn, a Linux privilege escalation vulnerability affecting the networkd-dispatcher service.
Nimbuspwn exploits weaknesses in the networkd-dispatcher service to traverse directories and execute arbitrary code with elevated privileges.
If confirmed malicious, this activity could allow an attacker to escalate privileges to root, potentially leading to full system compromise, persistent unauthorized access, and the ability to deploy additional malicious payloads.
Linux Suspicious Staging of Alternate System Files: endpointEndpointNoneversion:1
The following analytic detects the creation of sensitive system files such as nsswitch.conf, passwd, shadow, sudoers, and NSS shared libraries outside of their canonical /etc or /var/lib/docker paths.
This technique is associated with CVE-2025-32463 (chwoot), where an attacker stages a fake root directory containing spoofed system configuration files and NSS libraries to manipulate how privileged processes such as sudo resolve name services, enabling local privilege escalation by hijacking library loading without modifying the real /etc directory.
Linux Suspicious Privileged Container Execution: endpointEndpointNoneversion:1
The following analytic detects the execution of a Docker container with the privileged flag set, or with the pid namespace set to the host.
This can indicate a container running with elevated permissions and access to the underlying system. Actors can hide containers such as this to enable persistent access.
Linux Binary Executed from Shared Memory Directory: endpointEndpointNoneversion:1
The following analytic identifies the execution of a binary by root from Linux shared memory directories (/dev/shm/ and /run/shm/). Threat actors place executables in these directories to persist on high-uptime servers as system backdoors. Both /dev/shm and /run/shm are tmpfs-backed directories that exist only in virtual memory with no persistent storage, making them attractive for staging fileless or semi-fileless malware while avoiding disk forensics.
Linux Netcat Outbound Connection: endpointEndpointNoneversion:1
The following analytic detects outbound network connections originating from Netcat or Netcat-like binaries on Linux systems.
Netcat is a versatile networking utility that, while legitimate in some contexts, is frequently abused by attackers to establish reverse shells, exfiltrate data, or create persistent backdoor connections to remote systems.
This activity is significant because outbound connections from these binaries often indicate an active compromise, where an attacker may be maintaining command-and-control communication or tunneling malicious traffic.
If confirmed malicious, this could lead to unauthorized data exfiltration, lateral movement, or persistent remote access to the compromised system.
Linux Root Execution of id: endpointEndpointNoneversion:1
The following analytic detects the execution of the `id` command by the root user on Linux systems. Attackers commonly run `id` during post-exploitation to confirm they have achieved root-level privileges after a privilege escalation attempt.
This activity is significant because it may indicate an attacker is verifying superuser access following a successful compromise.
If confirmed malicious, this could signal that an attacker has gained full control of the system, enabling them to perform destructive actions, exfiltrate sensitive data, or establish persistent unauthorized access.
Linux Ghostscript Exploitation: endpointEndpointNoneversion:2
The following analytic detects exploitation of Ghostscript causing command execution.
This can be used by attackers to abuse file conversion services or embedded LibreOffice documents.
Linux Possible Privilege Escalation via PYTHONPATH: endpointEndpointNoneversion:1
The following analytic detects the creation of a malicious shared object at a Python importlib path outside the standard system library directories, a technique used to abuse PYTHONPATH for local privilege escalation.
Attackers exploiting vulnerabilities such as the 2024 NeedRestart flaw (CVE-2024-48990) plant a crafted importlib/__init__.so in an attacker-controlled directory, then manipulate the PYTHONPATH environment variable so that a privileged process, such as NeedRestart running as root, loads the rogue module instead of the legitimate one, achieving code execution with elevated privileges.
The detection monitors for file writes matching the importlib/__init__.so pattern that do not originate from expected system library paths.
Linux Suspicious Child Process of PostgreSQL: endpointEndpointNoneversion:1
The following analytic detects PostgreSQL spawning a shell, interpreter, or network utility as a child process.
When an attacker exploits a remote code execution vulnerability in PostgreSQL (such as via malicious COPY TO/FROM PROGRAM, CVE-2019-9193, or an insecurely configured extension), the database process itself becomes the parent of attacker-controlled commands.
Legitimate PostgreSQL processes do not normally fork shells or download tools, making this a high-fidelity signal for post-exploitation activity.
Linux MOTD Script Added: endpointEndpointNoneversion:1
The following analytic detects the creation of a file within the /etc/update-motd.d directory.
This is used to add scripts that run with Message of the Day (MOTD) when a user logs in.
This can be used by attackers for persistence if it contains malicious code.
Linux UDEV Rule Created: endpointEndpointNoneversion:1
The following analytic detects the creation of files within udev rules directories, including /etc/udev/rules.d and /usr/lib/udev/rules.d. Adversaries abuse udev rules to achieve persistent code execution by embedding RUN+= directives that trigger arbitrary commands whenever a matching device event occurs, such as a USB device being connected or a network interface coming online. Because udev rules execute in the context of the udev daemon with elevated privileges, this technique can provide both persistence and privilege escalation. It is used by post-exploitation frameworks such as PANIX and is effective on headless servers where device events still fire despite no interactive user session.
Linux Suspicious GCC Invocation Building Init Shared Object: endpointEndpointNoneversion:1
The following analytic detects compiler usage with flags commonly used to create shared libraries that auto-run initialization functions, which are often associated with local privilege escalation exploits.
Linux Possible System Binary Backdoor: endpointEndpointNoneversion:1
The following analytic detects the creation or overwrite of commonly targeted Linux system binaries such as cat, ls, cp, ps, mv, netstat, ss, and lsof.
Adversaries may replace these utilities with backdoored versions to hide malicious activity, harvest credentials, or maintain persistence while appearing to use legitimate system tools.
This technique is associated with rootkit deployment and post-exploitation frameworks such as PANIX.
Windows Suspicious QEMU Execution: endpointEndpointNoneversion:2
Detects execution of the QEMU binary and an image file with the -nographic flag.
This causes it to run in the background without any display.
This has been observed as a persistence and initial access technique by some threat actors to install a rogue linux virtual machine
Linux Suspicious XDG Autostart: endpointEndpointNoneversion:1
The following analytic detects the creation of a .desktop file within XDG autostart directories, including the system-wide /etc/xdg/autostart and user-local ~/.config/autostart paths.
Adversaries abuse XDG autostart entries to achieve persistence on Linux desktop environments — any .desktop file placed in these directories is automatically executed when a user logs into a graphical session.
This technique is used by post-exploitation frameworks such as PANIX to survive reboots without requiring root on user-local paths, or to achieve system-wide persistence when writing to /etc/xdg/autostart.
Linux Suspicious Docker Build Command Execution: endpointEndpointNoneversion:1
The following analytic detects docker build being executed on Dockerfiles within the /tmp directory.
This is not a typical location for this activity and can indicate an actor adding a container for malicious future actions.
Linux Shell Pseudo Device Reverse Shell: endpointEndpointNoneversion:1
The following analytic detects the use of shell's /dev/tcp or /dev/udp pseudo-device feature to establish outbound network connections.
This special file system interface allows opening a network socket and sending or receiving data using simple shell commands.
Attackers commonly abuse this native shell capability to create reverse shells without requiring external tools such as netcat, by redirecting shell I/O over a TCP or UDP connection to an attacker-controlled host and port.
Linux Usermod Root UID Set: endpointEndpointNoneversion:1
The following analytic detects the use of usermod to set a user's UID to 0. This functionally sets the user as a root user with full permissions. This approach can be used to bypass regular privilege escalation mechanisms, giving the attacker full control over the system while appearing as a regular user in most monitoring tools.