Suspicious Remote Payload Staging via curl Piped to Shell (via process_creation)

PremiumReviewedSigma · High · v1
Product
linux
Category
process_creation
Author
HuntRule
Published
2026-09-16
Updated
2026-09-16

ATT&CK techniques

C2
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Persistence

  6. Priv Esc

  7. Defense Evasion

  8. Cred Access

  9. Discovery

  10. Lateral Movement

  11. Collection

  12. Exfiltration

  13. Impact

What it detects

This rule detects curl silently fetching a remote script and piping it directly into a shell, the staging technique used to deploy the SNOWLIGHT loader after SAP NetWeaver exploitation. Downloading and executing remote content in a single pipeline bypasses on-disk inspection. This pattern is a common Linux post-exploitation loader behavior.

Related detections9 linkedT1105 — drag to rearrange
Suspicious curl Download Spawned by Excel via IQY Attachment (via process_creation)
Suspicious FRP Proxy Download via wget to Temporary Directory (via process_creation)
Suspicious DLL Download to ProgramData via Start-BitsTransfer (via process_creation)
Suspicious PowerShell Script Fetching Remote Batch File From Paste Site (via ps_script)
Suspicious PowerShell Download of Payload From Pastebin (via process_creation)
Suspicious PowerShell Remote Download and Execution via Invoke-WebRequest
Suspicious File Download to Shared Memory Directory on Linux
Malicious axios NPM Supply Chain C2 Domain Resolution
Suspicious Curl Download From Sysinternals Live Service (via process_creation)
Suspicious Remote Payload Staging via curl Piped to Shell (via process_creation)
Pivot detection · T1105 · 9 related

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.