elastic-protections
high
eql
Abnormally Large Shell Script Execution via Perl
Detects when Perl spawns a shell interpreter to execute an abnormally large script, indicated by a null command line despite having the expected argument count. This technique is commonly observed in npm typosquatting attacks where malicious packages use Perl as an intermediary to execute large embedded payloads that exceed normal command line size limits. Adversaries leverage Perl's trusted status to execute obfuscated or encoded shell scripts that perform credential harvesting, data exfiltrati