elastic-protections
high
eql
Suspicious Shell Command Execution via Node.js Parent
This rule detects when a shell command is executed as a child process of a Node.js process. Attackers may use Node.js to run shell commands for various malicious purposes, such as downloading and executing payloads, establishing persistence, or exfiltrating data.