Rule Info
Name
Linux Glob Based CLI Obfuscation
Author
Swachchhanda Shrawan Poudel (Nextron Systems)
Description
Detects the use of glob patterns to obfuscate command line arguments on Linux systems, which is a technique used by attackers to evade detection
Reference
Date
2026-03-04 00:00:00
Modified
None
Id
8a3b5e2f-9c4d-4a1e-b6c7-3f2e1d0a9b8c
Tags
attack.defense-evasion attack.t1027.010 attack.execution attack.t1059.004
Type
Nextron Sigma feed only (private)
