Node.Js Inline Script Network Connection - Linux

Rule Info

Name
Node.Js Inline Script Network Connection - Linux
Author
Swachchhanda Shrawan Poudel (Nextron Systems)
Description
Detects inline Node.js scripts that establish network connections, which may indicate malicious activity such as data exfiltration or command-and-control communication. Attackers may use inline Node.js scripts to quickly execute code that interacts with the network without leaving a persistent file on disk.
Date
2026-08-07 00:00:00
Modified
None
Id
64ca9236-8081-4e33-ad1f-9c852ff4dc34
Tags
attack.execution attack.t1059.004 attack.command-and-control attack.t1071.001
Type
Nextron Sigma feed only (private)

Rule History