Nginx service core dump after worker crash (signal 6)

Flags Nginx worker crashes that end with signal 6 core dumps, which may indicate serious issues or exploitation.

FreeReviewedSigma · High · v2
Service
nginx
Author
Florian Roth (Nextron Systems) (SigmaHQ), DRL 1.1
Published
2021-05-31
Updated
2026-07-31

ATT&CK techniques

Impact
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Persistence

  6. Priv Esc

  7. Defense Evasion

  8. Cred Access

  9. Discovery

  10. Lateral Movement

  11. Collection

  12. C2

  13. Exfiltration

What it detects

This rule flags log entries indicating an Nginx worker process “exited on signal 6 (core dumped),” which corresponds to a core dump being generated after a crash. Core dumps can indicate a serious stability or runtime problem and may also occur during exploitation attempts. The detection relies on Nginx service log messages that contain the specific core-dump wording.

Related detections2 linkedT1499.004 — drag to rearrange
Windows Audit-CVE: User Applications Writing CveEventWrite Events (Event ID 1)
Apache worker crash logs with "Segmentation Fault" exit signal
Nginx service core dump after worker crash (signal 6)
Pivot detection · T1499.004 · 2 related

Changelog

v2
  1. v2
    Candidate ingested via manual entry.2026-07-31
  2. v1
    No changelog recorded for this version.2026-07-30

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.