Rule Info
Name
Suspicious Double Extension Files in Linux
Author
Swachchhanda Shrawan Poudel (Nextron Systems)
Description
Detects files with double extensions in Linux systems, which could be an attempt to disguise executable content as harmless documents.
Date
2026-02-05 00:00:00
Modified
None
Id
47f2bca9-e8d4-4f38-9a8e-45c789432d10
Tags
attack.defense-evasion attack.t1036.007 attack.initial-access attack.t1566.001
Type
Nextron Sigma feed only (private)
