Linux File Creation: Filename Contains Embedded Base64 Bash Fragments

Alerts on Linux file events for filenames that appear to embed Base64-decoding bash command patterns.

FreeReviewedSigma · High · v3
Product
linux
Category
file_event
Author
@kostastsale (SigmaHQ), DRL 1.1
Published
2025-11-22
Updated
2026-07-31

ATT&CK techniques

Execution → Defense Evasion
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Persistence

  5. Priv Esc

  6. Cred Access

  7. Discovery

  8. Lateral Movement

  9. Collection

  10. C2

  11. Exfiltration

  12. Impact

What it detects

This rule flags Linux file events where the filename contains specific substrings indicative of embedded Base64 decoding and bash-style command fragments. Such naming can be used to smuggle shell commands into workflows that later process filenames, enabling stealthy execution of hidden payloads. It relies on file event telemetry that includes the full target filename and matches the presence of the defined suspicious markers within that name.

Related detections9 linkedT1027 — drag to rearrange
Linux File Creation with Unusually Long Filenames (100+ Characters)
Suspicious Shell Command Obfuscation via printf Escape Encoding on VMware ESXi (via process_creation)
Suspicious Bad Apples Reverse Shell via socat pty
Suspicious Axios NPM macOS Persistence Masquerading as Apple Service
Malicious Emmenhtal JavaScript Loader Spawning Encoded PowerShell
Suspicious Python Interpreter Launching Encoded PowerShell via subprocess
Suspicious PowerShell Download Of Text-Disguised Payload
Suspicious Encrypted Implant File Creation for DLL Search Order Hijacking (RainyDay Turian PlugX)
Suspicious PS1Bot PowerShell Payload Written to ProgramData (via file_event)
Linux File Creation: Filename Contains Embedded Base64 Bash Fragments
Pivot detection · T1027 · 9 related

Changelog

v3
  1. v3
    Candidate ingested via manual entry.2026-07-31
  2. v2
    Candidate ingested via manual entry.2026-07-31
  3. v1
    No changelog recorded for this version.2026-07-30

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.