Linux process execution of shell via nice utility
Flags Linux process creation where nice is used to spawn a shell (bash/dash/fish/sh/zsh).
- Product
- linux
- Category
- process_creation
- Author
- Li Ling, Andy Parkidomo, Robert Rakowski, Blake Hartstein (Bloomberg L.P.) (SigmaHQ), DRL 1.1
- Published
- 2024-09-02
- Updated
- 2026-07-31
ATT&CK techniques
DiscoveryRecon
Resource Dev
Initial Access
Execution
Persistence
Priv Esc
Defense Evasion
Cred Access
Discovery
Lateral Movement
Collection
C2
Exfiltration
Impact
What it detects
This rule identifies use of the Linux "nice" utility where the process image path ends with /nice and the command line ends with a common shell binary (e.g., /bin/bash, /bin/sh, /bin/zsh). Attackers may leverage such execution to run interactive shells or bypass restricted execution paths for unauthorized command execution. The detection relies on process creation telemetry containing the executable path and full command line.
Reporting behind it
- gtfobins.github.iohttps://gtfobins.github.io/gtfobins/nice/#shell
- elastic.cohttps://www.elastic.co/guide/en/security/current/linux-restricted-shell-breakout-via-linux-binary-s.html
- github.comhttps://github.com/SigmaHQ/sigma/blob/master/rules/linux/process_creation/proc_creation_lnx_nice_shell_execution.yml
Changelog
v2- v2Candidate ingested via manual entry.2026-07-31
- v1No changelog recorded for this version.2026-07-30
Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.
title: Linux process execution of shell via nice utility
id: c8412364-8340-4a70-ad95-be156c22b0cc
status: test
description: This rule identifies use of the Linux "nice" utility where the process image path ends with /nice and the command line ends with a common shell binary (e.g., /bin/bash, /bin/sh, /bin/zsh). Attackers may leverage such execution to run interactive shells or bypass restricted execution paths for unauthorized command execution. The detection relies on process creation telemetry containing the executable path and full command line.
references:
- https://gtfobins.github.io/gtfobins/nice/#shell
- https://www.elastic.co/guide/en/security/current/linux-restricted-shell-breakout-via-linux-binary-s.html
- https://github.com/SigmaHQ/sigma/blob/master/rules/linux/process_creation/proc_creation_lnx_nice_shell_execution.yml
author: Li Ling, Andy Parkidomo, Robert Rakowski, Blake Hartstein (Bloomberg L.P.), Huntrule Team
date: 2024-09-02
tags:
- attack.discovery
- attack.t1083
logsource:
category: process_creation
product: linux
detection:
selection:
Image|endswith: /nice
CommandLine|endswith:
- /bin/bash
- /bin/dash
- /bin/fish
- /bin/sh
- /bin/zsh
condition: selection
falsepositives:
- Unknown
level: high
license: DRL-1.1
related:
- id: 093d68c7-762a-42f4-9f46-95e79142571a
type: derived