Rule Info
Name
Node.Js Inline Script Network Connection
Author
Swachchhanda Shrawan Poudel (Nextron Systems)
Description
Detects inline Node.js scripts that establish network connections, which may indicate malicious activity such as data exfiltration or command-and-control communication.
Attackers may use inline Node.js scripts to quickly execute code that interacts with the network without leaving a persistent file on disk.
Date
2026-08-07 00:00:00
Modified
None
Id
1ff7ba21-e6a7-4603-beba-b70d28fb74e1
Tags
attack.execution attack.t1059.004 attack.command-and-control attack.t1071.001
Type
Nextron Sigma feed only (private)
