Suspicious Base64 Decoded Payload Piped to Shell

PremiumReviewedSigma · High · v1
Product
linux
Category
process_creation
Author
HuntRule
Published
2026-09-13
Updated
2026-09-13

ATT&CK techniques

Execution → Defense Evasion
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Persistence

  5. Priv Esc

  6. Cred Access

  7. Discovery

  8. Lateral Movement

  9. Collection

  10. C2

  11. Exfiltration

  12. Impact

What it detects

This rule detects an echoed base64 blob being decoded and piped directly into an interactive shell on Linux, an obfuscated execution technique used after ActiveMQ CVE-2023-46604 exploitation. Attackers use this to hide payload contents and run commands without dropping a file. Chaining base64 decode into bash is rarely legitimate and indicates obfuscated code execution.

Related detections9 linkedT1059.004 — drag to rearrange
Linux File Creation with Unusually Long Filenames (100+ Characters)
Linux File Creation: Filename Contains Embedded Base64 Bash Fragments
Suspicious Reverse Shell via Dev TCP or Netcat
Suspicious Shell Spawned by ActiveMQ Java Process
Suspicious Shell Command Obfuscation via printf Escape Encoding on VMware ESXi (via process_creation)
Suspicious Bad Apples Reverse Shell via socat pty
Suspicious Axios NPM macOS Persistence Masquerading as Apple Service
Malicious Emmenhtal JavaScript Loader Spawning Encoded PowerShell
Suspicious Python Interpreter Launching Encoded PowerShell via subprocess
Suspicious Base64 Decoded Payload Piped to Shell
Pivot detection · T1059.004 · 9 related

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.