Linux Log File Alerts for Suspicious Messages

Generates alerts when Linux log text contains suspicious keywords indicating possible network, service, or logging disruption.

FreeReviewedSigma · Medium · v3
Product
linux
Author
Florian Roth (Nextron Systems) (SigmaHQ), DRL 1.1
Published
2017-03-25
Updated
2026-07-31

What it detects

This rule flags Linux log entries containing specific keywords associated with risky system or network states and log anomalies. Attackers and post-compromise activity may produce messages like entering promiscuous mode, service deactivation, oversized packet indicators, or dropped log messages that can reflect reconnaissance, interference, or disruption attempts. Detection relies on text keyword matches within Linux log data streams for the listed phrases.

Changelog

v3
  1. v3
    Candidate ingested via manual entry.2026-07-31
  2. v2
    Candidate ingested via manual entry.2026-07-31
  3. v1
    No changelog recorded for this version.2026-07-30

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.