Linux process execution of shell via nice utility

Flags Linux process creation where nice is used to spawn a shell (bash/dash/fish/sh/zsh).

FreeReviewedSigma · High · v2
Product
linux
Category
process_creation
Author
Li Ling, Andy Parkidomo, Robert Rakowski, Blake Hartstein (Bloomberg L.P.) (SigmaHQ), DRL 1.1
Published
2024-09-02
Updated
2026-07-31
title: Linux process execution of shell via nice utility
id: c8412364-8340-4a70-ad95-be156c22b0cc
status: test
description: This rule identifies use of the Linux "nice" utility where the process image path ends with /nice and the command line ends with a common shell binary (e.g., /bin/bash, /bin/sh, /bin/zsh). Attackers may leverage such execution to run interactive shells or bypass restricted execution paths for unauthorized command execution. The detection relies on process creation telemetry containing the executable path and full command line.
references:
  - https://gtfobins.github.io/gtfobins/nice/#shell
  - https://www.elastic.co/guide/en/security/current/linux-restricted-shell-breakout-via-linux-binary-s.html
  - https://github.com/SigmaHQ/sigma/blob/master/rules/linux/process_creation/proc_creation_lnx_nice_shell_execution.yml
author: Li Ling, Andy Parkidomo, Robert Rakowski, Blake Hartstein (Bloomberg L.P.), Huntrule Team
date: 2024-09-02
tags:
  - attack.discovery
  - attack.t1083
logsource:
  category: process_creation
  product: linux
detection:
  selection:
    Image|endswith: /nice
    CommandLine|endswith:
      - /bin/bash
      - /bin/dash
      - /bin/fish
      - /bin/sh
      - /bin/zsh
  condition: selection
falsepositives:
  - Unknown
level: high
license: DRL-1.1
related:
  - id: 093d68c7-762a-42f4-9f46-95e79142571a
    type: derived