Linux Log Shellshock Expression Pattern Matching

Identifies Shellshock-style function-body expressions in Linux log data via keyword string matches.

FreeReviewedSigma · High · v3
Product
linux
Author
Florian Roth (Nextron Systems) (SigmaHQ), DRL 1.1
Published
2017-03-14
Updated
2026-07-31

ATT&CK techniques

Persistence
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Priv Esc

  6. Defense Evasion

  7. Cred Access

  8. Discovery

  9. Lateral Movement

  10. Collection

  11. C2

  12. Exfiltration

  13. Impact

What it detects

This rule flags Shellshock-style function expression sequences appearing in Linux log files, including variations of (){:;}; and spaced variants. Such payload markers are used to trigger Bash function parsing behavior and can indicate attempted command injection. The detection relies on keyword matches in available text-based telemetry from Linux logging sources.

Related detections9 linkedT1505.003 — drag to rearrange
Suspicious SD-WAN Compromise JSP Webshell Access
Malicious AquaShell Webshell Access on Cisco Secure Email Gateway by UAT-9686
Malicious IIS Worker Process Spawning Command Shell Reconnaissance
Malicious StyleSmuggler (CVE-2026-75650) Web Shell Dropped In Magento Product Image Cache (via file_event)
Suspicious Web Shell File Written to IIS wwwroot Directory
Possible Citrix ShareFile Unauthenticated Upload Path Traversal Webshell (CVE-2023-24489) (via webserver)
Possible Unauthenticated Admin Creation in Dynamicweb CVE-2022-25369
Possible DotCMS Path Traversal Webshell Upload via content API CVE-2022-26352
Possible Avaya Aura Device Services WebDAV PHP Webshell Upload via PhoneBackup (via webserver)
Linux Log Shellshock Expression Pattern Matching
Pivot detection · T1505.003 · 9 related

Changelog

v3
  1. v3
    Candidate ingested via manual entry.2026-07-31
  2. v2
    Candidate ingested via manual entry.2026-07-31
  3. v1
    No changelog recorded for this version.2026-07-30

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.