Linux File Creation with Unusually Long Filenames (100+ Characters)

Flags Linux file creations with filenames 100+ characters long, excluding specific known benign system paths, to support threat hunting.

FreeReviewedSigma · Low · v5
Product
linux
Category
file_event
Author
@kostastsale (SigmaHQ), DRL 1.1
Published
2025-11-22
Updated
2026-07-31

ATT&CK techniques

Execution → Defense Evasion
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Persistence

  5. Priv Esc

  6. Cred Access

  7. Discovery

  8. Lateral Movement

  9. Collection

  10. C2

  11. Exfiltration

  12. Impact

What it detects

This rule flags file creation events where the target filename ends with at least 100 characters, which can be used to hinder analysis or evade simpler pattern-based detections. Attackers may choose long, irregular filenames to make malicious artifacts harder to locate and classify. It relies on Linux file event telemetry that provides the full TargetFilename and supports filtering out specific known benign path prefixes.

Related detections9 linkedT1027 — drag to rearrange
Linux File Creation: Filename Contains Embedded Base64 Bash Fragments
Suspicious Shell Command Obfuscation via printf Escape Encoding on VMware ESXi (via process_creation)
Suspicious Bad Apples Reverse Shell via socat pty
Suspicious Axios NPM macOS Persistence Masquerading as Apple Service
Malicious Emmenhtal JavaScript Loader Spawning Encoded PowerShell
Suspicious Python Interpreter Launching Encoded PowerShell via subprocess
Suspicious PowerShell Download Of Text-Disguised Payload
Suspicious Encrypted Implant File Creation for DLL Search Order Hijacking (RainyDay Turian PlugX)
Suspicious PS1Bot PowerShell Payload Written to ProgramData (via file_event)
Linux File Creation with Unusually Long Filenames (100+ Characters)
Pivot detection · T1027 · 9 related

Changelog

v5
  1. v5
    Candidate ingested via manual entry.2026-07-31
  2. v4
    Candidate ingested via manual entry.2026-07-31
  3. v3
    Candidate ingested via manual entry.2026-07-31
  4. v2
    Candidate ingested via manual entry.2026-07-31
  5. v1
    No changelog recorded for this version.2026-07-30

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.