sigmaDRL-1.1from SigmaHQ/sigma
Suspicious Download and Execute Pattern via Curl/Wget
Detects suspicious use of command-line tools such as curl or wget to download remote content - particularly scripts - into temporary directories (e.g., /dev/shm, /tmp), followed by immediate execution, indicating potential malicious activity. This pattern is commonly used by malicious scripts, stagers, or downloaders in fileless or multi-stage Linux attacks.
Quality
76
FP risk
โ
Forks
0
Views
1
Rule source๐ locked
๐
Sign in to view the rule source
Free accounts can view the source for the top-ranked rules. Create one in seconds โ no credit card required.
Sign in โ