Linux nohup Execution from /tmp
Flags Linux process executions using nohup with command lines referencing /tmp.
FreeReviewedSigma · High · v2
- Product
- linux
- Category
- process_creation
- Author
- Joseliyo Sanchez, @Joseliyo_Jstnk (SigmaHQ), DRL 1.1
- Published
- 2023-06-02
- Updated
- 2026-07-31
What it detects
This rule flags process creation where the executable path ends with "nohup" and the command line contains "/tmp/", indicating use of nohup from a potentially transient or attacker-controlled location. Attackers commonly leverage nohup to keep commands running after disconnects while staging binaries or scripts in temporary directories. It relies on Linux process creation telemetry with captured image paths and command-line arguments.
Reporting behind it
- blogs.jpcert.or.jphttps://blogs.jpcert.or.jp/en/2023/05/gobrat.html
- jstnk9.github.iohttps://jstnk9.github.io/jstnk9/research/GobRAT-Malware/
- virustotal.comhttps://www.virustotal.com/gui/file/60bcd645450e4c846238cf0e7226dc40c84c96eba99f6b2cffcd0ab4a391c8b3/detection
- virustotal.comhttps://www.virustotal.com/gui/file/3e44c807a25a56f4068b5b8186eee5002eed6f26d665a8b791c472ad154585d1/detection
- github.comhttps://github.com/SigmaHQ/sigma/blob/master/rules/linux/process_creation/proc_creation_lnx_nohup_susp_execution.yml
Changelog
v2- v2Candidate ingested via manual entry.2026-07-31
- v1No changelog recorded for this version.2026-07-30
Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.
linux-suspicious-nohupp-execution-from-tmp-457df417
title: Linux nohup Execution from /tmp
id: f1e347f3-c06c-4e1e-bbac-1ae11bda6722
related:
- id: e4ffe466-6ff8-48d4-94bd-e32d1a6061e2
type: derived
- id: 457df417-8b9d-4912-85f3-9dbda39c3645
type: derived
status: test
description: This rule flags process creation where the executable path ends with "nohup" and the command line contains "/tmp/", indicating use of nohup from a potentially transient or attacker-controlled location. Attackers commonly leverage nohup to keep commands running after disconnects while staging binaries or scripts in temporary directories. It relies on Linux process creation telemetry with captured image paths and command-line arguments.
references:
- https://blogs.jpcert.or.jp/en/2023/05/gobrat.html
- https://jstnk9.github.io/jstnk9/research/GobRAT-Malware/
- https://www.virustotal.com/gui/file/60bcd645450e4c846238cf0e7226dc40c84c96eba99f6b2cffcd0ab4a391c8b3/detection
- https://www.virustotal.com/gui/file/3e44c807a25a56f4068b5b8186eee5002eed6f26d665a8b791c472ad154585d1/detection
- https://github.com/SigmaHQ/sigma/blob/master/rules/linux/process_creation/proc_creation_lnx_nohup_susp_execution.yml
author: Joseliyo Sanchez, @Joseliyo_Jstnk, Huntrule Team
date: 2023-06-02
tags:
- attack.execution
logsource:
product: linux
category: process_creation
detection:
selection:
Image|endswith: /nohup
CommandLine|contains: /tmp/
condition: selection
falsepositives:
- Unknown
level: high
license: DRL-1.1