Techniques
Sample rules
Nohup Execution
- source: sigma
- technicques:
- t1059
- t1059.004
Description
Detects usage of nohup which could be leveraged by an attacker to keep a process running or break out from restricted environments
Detection logic
condition: selection
selection:
Image|endswith: /nohup