Vim GTFOBin Abuse - Linux

 Original Source: [Sigma source]
Title: Vim GTFOBin Abuse - Linux
Status: test
Description:Detects the use of "vim" and it's siblings commands to execute a shell or proxy commands. Such behavior may be associated with privilege escalation, unauthorized command execution, or to break out from restricted environments.
References:
  -https://gtfobins.github.io/gtfobins/vi/
  -https://gtfobins.github.io/gtfobins/vim/
  -https://gtfobins.github.io/gtfobins/rvim/
  -https://gtfobins.github.io/gtfobins/vimdiff/
Author: Nasreddine Bencherchali (Nextron Systems), Luc Génaux
Date: 2022-12-28
modified:2026-06-05
Tags:
  • -'attack.execution'
  • -'attack.discovery'
  • -'attack.t1059'
  • -'attack.t1083'
Logsource:
  • category: process_creation
  • product: linux
Detection:
  selection_img:
    Image|endswith:
      -'/rvim'
      -'/vi'
      -'/vim'
      -'/vimdiff'

    CommandLine|contains:
      -' --cmd '
      -' -c'

  selection_cli:
    CommandLine|contains:
      -':!/'
      -':!$'
      -':!..'
      -':lua '
      -':py '
      -':shell'
      -'/bin/bash'
      -'/bin/dash'
      -'/bin/fish'
      -'/bin/sh'
      -'/bin/csh'
      -'/bin/ksh'
      -'/bin/zsh'
      -'/bin/tmux'

  condition:all of selection_*
Falsepositives:
  -Unknown
Level: high