
Rule Info
Name
Suspicious Python Zlib and Base64 One-liner Execution
Author
Swachchhanda Shrawan Poudel (Nextron Systems)
Description
Detects Python command line execution using zlib decompression and base64 with decode functions, often used for executing obfuscated payloads.
Threat actors may use this technique to execute malicious encoded code in a single line, which can be indicative of attempts to bypass security measures or deliver payloads in a stealthy manner.
Reference
Date
2025-05-28 00:00:00
Modified
None
Id
2e7d8c3e-2b6a-4e8c-9e7d-1b2a3c4d5e6f
Tags
attack.execution attack.t1059.006 attack.defense-evasion attack.t1027.010
Type
Nextron Sigma feed only (private)