Browse Rules

Search and filter across all detection sources

45 rules

elastic-protections high eql

Command and Scripting Interpreter from Suspicious Parent

Identifies when a script interpreter is executed with a long command line and from an unsigned parent executable.

panther medium python

Teleport Suspicious Commands Executed

A user has invoked a suspicious command that could lead to a host compromise

panther medium python

User Logged in as root

A User logged in as root

elastic-protections high eql

Suspicious Apple Script Execution

Identifies the execution of the Apple script interpreter (osascript) process with suspicious command line arguments. This behavior is consistent with an attacker executing malicious scripts for execution or command and control.

elastic-protections high eql

Suspicious Large Script Execution via Shell Command

Detects when a script interpreter or unsigned/untrusted binary executes an abnormally large shell command. Many different types of macOS malware will hardcode large shell or apple scripts and execute them via a shell command.

anvilogic medium spl

Swift Script Execution - MacOS [splunk-edr]

Adversaries may abuse command and script interpreters to execute commands, scripts, or binaries. These interfaces and languages provide ways of interacting with computer systems and are a common feature across many different platforms. Adversaries may abuse these technologies in various ways as a means of executing arbitrary commands. This use case detects Swift scripts executed from the command line.

anvilogic medium other

Swift Script Execution - MacOS [snowflake-crowdstrikefdr_process]

Adversaries may abuse command and script interpreters to execute commands, scripts, or binaries. These interfaces and languages provide ways of interacting with computer systems and are a common feature across many different platforms. Adversaries may abuse these technologies in various ways as a means of executing arbitrary commands. This use case detects Swift scripts executed from the command line.

elastic medium eql

Apple Script Execution followed by Network Connection

Detects execution via the Apple script interpreter (osascript) followed by a network connection from the same process within a short time period. Adversaries may use malicious scripts for execution and command and control.

elastic medium eql

Remote File Download via Script Interpreter

Identifies built-in Windows script interpreters (cscript.exe or wscript.exe) being used to download an executable file from a remote destination.

panther medium python

Upwind Runtime Detection Passthrough

Re-raises Upwind runtime security detections in Panther. Covers process execution anomalies, syscall-based threats, container escapes, and other host/container behavioral threats.

panther informational python

Azure Serverless Script Execution

Detects when serverless resources execute PowerShell or Python scripts through Azure Automation runbook jobs or Azure Function Apps. Adversaries may abuse access to serverless resources to execute commands with inherited permissions from managed identities, RunAs accounts, or hybrid worker groups.

elastic high kql

Long Base64 Encoded Command via Scripting Interpreter

Identifies oversized command lines used by Python, PowerShell, Node.js, or Deno that contain base64 decoding or encoded-command patterns. Adversaries may embed long inline encoded payloads in scripting interpreters to evade inspection and execute malicious content across Windows, macOS, and Linux systems.

elastic-protections high eql

Suspicious Execution from a Windows Script

Identifies a Windows script interpreter executing for more than 5 minutes followed by spawning a child process. This may indicate long term network activity from a Windows script which is common pattern of a command and control backdoor via malicious scripts.

elastic-protections high eql

Potential Command and Control via Windows Scripts

Identifies the execution of a Windows script interpreter followed by a network connection or DNS loookup request after 5 minutes of the process start. This may indicate long term network activity from a Windows script which is common pattern of a command and control backdoor via malicious scripts.

elastic medium eql

Script Interpreter Connection to Non-Standard Port

Detects the execution of a script interpreter followed by an outbound network connection to a raw IP address on a non-standard port. Many initial access scripts and malware implants connect directly to C2 or payload servers using non-standard ports to avoid detection.

anvilogic medium spl

Sliver C2 Implant Activity Pattern [splunk-edr]

Adversaries may abuse command and script interpreters to execute commands, scripts, or binaries. These interfaces and languages provide ways of interacting with computer systems and are a common feature across many different platforms. Most systems come with some built-in command-line interface and scripting capabilities, for example, macOS and Linux distributions include some flavor of Unix Shell while Windows installations include the Windows Command Shell and PowerShell. This use case detects

anvilogic medium spl

Sliver C2 Implant Activity Pattern [splunk-powershell]

Adversaries may abuse command and script interpreters to execute commands, scripts, or binaries. These interfaces and languages provide ways of interacting with computer systems and are a common feature across many different platforms. Most systems come with some built-in command-line interface and scripting capabilities, for example, macOS and Linux distributions include some flavor of Unix Shell while Windows installations include the Windows Command Shell and PowerShell. This use case detects

anvilogic medium spl

Sliver C2 Implant Activity Pattern [splunk-sysmon]

Adversaries may abuse command and script interpreters to execute commands, scripts, or binaries. These interfaces and languages provide ways of interacting with computer systems and are a common feature across many different platforms. Most systems come with some built-in command-line interface and scripting capabilities, for example, macOS and Linux distributions include some flavor of Unix Shell while Windows installations include the Windows Command Shell and PowerShell. This use case detects

anvilogic medium spl

Sliver C2 Implant Activity Pattern [splunk-winevent]

Adversaries may abuse command and script interpreters to execute commands, scripts, or binaries. These interfaces and languages provide ways of interacting with computer systems and are a common feature across many different platforms. Most systems come with some built-in command-line interface and scripting capabilities, for example, macOS and Linux distributions include some flavor of Unix Shell while Windows installations include the Windows Command Shell and PowerShell. This use case detects

anvilogic medium spl

Git Spawns System32 Process [splunk-sysmon]

Adversaries may abuse command and script interpreters to execute commands, scripts, or binaries with the help of Git hooks. These interfaces and languages provide ways of interacting with computer systems and are a common feature across many different platforms. Most systems come with some built-in command-line interface and scripting capabilities, for example, Windows installations include the Windows Command Shell and PowerShell. This use case detects Git hooks spawning a System32 process. Not

anvilogic medium spl

Git Hooks Spawn System32 Process [splunk-sysmon]

Adversaries may abuse command and script interpreters to execute commands, scripts, or binaries with the help of Git hooks. These interfaces and languages provide ways of interacting with computer systems and are a common feature across many different platforms. Most systems come with some built-in command-line interface and scripting capabilities, for example, Windows installations include the Windows Command Shell and PowerShell. This use case detects Git hooks spawning a System32 process. Not

anvilogic medium spl

Git Spawns System32 Process [splunk-winevent]

Adversaries may abuse command and script interpreters to execute commands, scripts, or binaries with the help of Git hooks. These interfaces and languages provide ways of interacting with computer systems and are a common feature across many different platforms. Most systems come with some built-in command-line interface and scripting capabilities, for example, Windows installations include the Windows Command Shell and PowerShell. This use case detects Git hooks spawning a System32 process. Not

elastic-protections high eql

BCDEdit Safe Mode Command Execution

Identifies when the command-line tool for managing Boot Configuration Data (BCDEdit.exe) is spawned from an untrusted process, office application, or script interpreter and used to specify a reboot into Safe Mode.

anvilogic high spl

Parent in Public Folder Suspicious Process [splunk-sysmon]

Adversaries may attempt to hide artifacts associated with their behaviors to evade detection. Adversaries may abuse command and script interpreters to execute commands, scripts, or binaries. This use case detects suspicious processes with a parent process in the Users\Public directory.

anvilogic high spl

Parent in Public Folder Suspicious Process [splunk-winevent]

Adversaries may attempt to hide artifacts associated with their behaviors to evade detection. Adversaries may abuse command and script interpreters to execute commands, scripts, or binaries. This use case detects suspicious processes with a parent process in the Users\Public directory.