Suspicious Double Extension File Execution on Linux

Rule Info

Name
Suspicious Double Extension File Execution on Linux
Author
Swachchhanda Shrawan Poudel (Nextron Systems)
Description
Detects suspicious use of executable extensions like .sh, .py or .pl after a non-executable file extension to disguise malicious files in Linux environments
Date
2026-02-05 00:00:00
Modified
None
Id
103696eb-1ef2-476b-851b-927d5b2fdb81
Tags
attack.initial-access attack.t1566.001 attack.defense-evasion attack.t1036.007
Type
Nextron Sigma feed only (private)

Rule History