Skip to content
Threat Feed
low advisory

Detection of Suspicious Process Backgrounding on Linux

This brief outlines the detection of Linux shell processes that are backgrounded via the ampersand operator by unusual parent processes, a technique used to evade monitoring and obfuscate process hierarchies.

Adversaries targeting Linux environments often employ techniques to obscure their activities by disassociating malicious processes from the parent process chain. A common method involves launching shell interpreters (such as bash, zsh, or sh) with the '&' operator, which backgrounds the task and allows it to run independently of the originating terminal. By initiating these processes from unusual or unexpected parent processes, attackers attempt to evade detection mechanisms that monitor process lineage. This threat intelligence focuses on identifying these anomalies by flagging shell executions that utilize backgrounding operators when spawned by processes outside of a known-good allowlist of system services.

Attack Chain

  1. An attacker gains initial access or escalation on a Linux endpoint.
  2. The attacker identifies a target script or command to execute for malicious intent (e.g., C2 beaconing).
  3. The attacker attempts to minimize detection by breaking the process tree.
  4. The attacker launches the shell interpreter with the backgrounding operator '&' (e.g., sh -c 'script.sh &').
  5. The parent process is either a non-standard utility or a compromised service that is not typically expected to spawn shells.
  6. The shell process continues to run in the background after the parent process potentially terminates or finishes its task.
  7. The objective (exfiltration, persistence, or secondary payload execution) is completed while the process remains detached from the primary user session.

Impact

Successful exploitation of this technique allows adversaries to hide their presence in system logs, complicate forensic investigations, and maintain persistence. While the risk score for individual instances is low, this activity may serve as a precursor or camouflage for more damaging objectives such as data exfiltration or the deployment of additional malware.

Recommendation

Detection engineering teams should implement monitoring for process start events where shell interpreters are initiated with the ampersand backgrounding operator by unusual parents.

  • Deploy the Sigma rule below to identify anomalous shell backgrounding activity.
  • Review and establish an allowlist of legitimate parent processes that perform background tasks in your specific environment (e.g., automation agents, specific cron jobs).
  • Enable process creation logging (via Auditd, Sysmon for Linux, or EDR telemetry) to capture process.parent.name and process.args for all process start events.
  • Investigate any alerts generated by this logic by correlating the process lineage and user context to distinguish between routine administrative automation and potential adversary evasion.

Immediate actions

Deploy the Sigma rule to a test environment to identify baseline noise.

Detection Engineering 72h

Threat Hunt

Search for shell command lines containing the '&' character spawned by non-shell/non-ssh parents.

T1059.004 medium medium confidence hunt now

Data: Process creation events

Detection coverage 1

Detect Suspicious Process Backgrounding by Unusual Parent

low

Detects shell interpreters spawned by unusual parent processes using the backgrounding '&' operator, which may indicate an attempt to evade detection.

sigma tactics: defense_evasion, execution techniques: T1036.009, T1059.004 sources: process_creation, linux

Detection queries are available on the platform. Get full rules →