Inline Python Execution - Spawn Shell Via OS System Library

Rule Info

Name
Inline Python Execution - Spawn Shell Via OS System Library
Author
Li Ling, Andy Parkidomo, Robert Rakowski, Blake Hartstein (Bloomberg L.P.)
Description
Detects execution of inline Python code via the "-c" in order to call the "system" function from the "os" library, and spawn a shell.
Date
2024-09-02 00:00:00
Modified
None
Id
2d2f44ff-4611-4778-a8fc-323a0e9850cc
Tags
attack.execution attack.t1059 DEMO
Type
Community Rule

Rule History

Author
Title
Date
Commit
Murphy0801
Merge PR #4975 from @Murphy0801 - Add new rules related to GTFOBins
2024-09-02