Rule Info
Name
Suspicious Linux Command Patterns
Author
Swachchhanda Shrawan Poudel (Nextron Systems)
Description
Detects suspicious command line patterns that may indicate malicious activity such as decoding base64 content to files in some folder and executing it.
Date
2026-02-05 00:00:00
Modified
None
Id
5bc56939-a7e7-4334-a0b7-171200c29d9e
Tags
attack.execution attack.t1059.004 attack.defense-evasion attack.t1027
Type
Nextron Sigma feed only (private)
