LoFP LoFP / administrators or installed processes that leverage nohup

Techniques

Sample rules

Nohup Execution

Description

Detects usage of nohup which could be leveraged by an attacker to keep a process running or break out from restricted environments

Detection logic

condition: selection
selection:
  Image|endswith: /nohup