Rule Info
Name
Shell Invocation via Env Command - Linux
Author
Li Ling, Andy Parkidomo, Robert Rakowski, Blake Hartstein (Bloomberg L.P.)
Description
Detects the use of the env command to invoke a shell. This may indicate an attempt to bypass restricted environments, escalate privileges, or execute arbitrary commands.
Date
2024-09-02 00:00:00
Modified
None
Id
bed978f8-7f3a-432b-82c5-9286a9b3031a
Tags
attack.execution attack.t1059
Type
Community Rule
Link to Public Repo
Rule History
Author
Title
Date
Commit