Rule Info
Name
Potentially Suspicious PyInstaller Executable
Author
Swachchhanda Shrawan Poudel (Nextron Systems)
Description
Detects execution of potentially suspicious PyInstaller executables that have been packaged with python code which may include malicious payloads.
PyInstaller is a popular tool for packaging Python applications into standalone executables, but it can also be used by adversaries to wrap and obfuscate malicious python code into a single executable file.
Reference
Internal Research
Date
2026-01-27 00:00:00
Modified
None
Id
5f4f7248-2fff-4b91-8976-af7e7a1bbb6e
Tags
attack.execution attack.t1204.002 attack.defense-evasion attack.t1027
Type
Nextron Sigma feed only (private)
