Shell Invocation via Env Command - Linux

 Original Source: [Sigma source]
Title: Shell Invocation via Env Command - Linux
Status: test
Description:Detects the use of the env command to invoke a shell. This may indicate an attempt to bypass restricted environments, escalate privileges, or execute arbitrary commands.
References:
  -https://gtfobins.github.io/gtfobins/env/#shell
  -https://www.elastic.co/guide/en/security/current/linux-restricted-shell-breakout-via-linux-binary-s.html
Author: Li Ling, Andy Parkidomo, Robert Rakowski, Blake Hartstein (Bloomberg L.P.)
Date: 2024-09-02
modified:2026-01-08
Tags:
  • -'attack.execution'
  • -'attack.t1059.004'
Logsource:
  • category: process_creation
  • product: linux
Detection:
  selection:
    Image|endswith: '/env'
    CommandLine|contains:
      -'/bin/bash'
      -'/bin/dash'
      -'/bin/fish'
      -'/bin/sh'
      -'/bin/zsh'

  condition:selection
Falsepositives:
  -Github operations such as ghe-backup
Level: high