Detection of First-Time Python-Initiated Shell Execution on macOS
This detection monitors for the first time a Python process spawns a shell on a macOS host, a common indicator of post-exploitation activity such as malicious model deserialization or compromised dependency execution.
This detection focuses on identifying anomalous behavior where a Python process initiates an interactive or command-line shell session on macOS. Adversaries frequently leverage Python-based execution for malicious purposes, including the deserialization of malicious machine learning models (e.g., using pickle or PyTorch __reduce__) and the execution of backdoored software dependencies.
Since legitimate Python applications rarely require spawning shell commands (e.g., bash, zsh) via the -c flag, the first occurrence of this behavior on a host is a significant signal of potential compromise. This approach is intended to distinguish between established, baseline Python workflows and novel execution patterns. The detection logic excludes common administrative tools such as pip, conda, brew, and jupyter to minimize noise, making it suitable for identifying unauthorized post-exploitation reconnaissance, persistence, or reverse shell activity.
Impact
Successful exploitation allows attackers to execute arbitrary system commands with the privileges of the Python process. Observed techniques often facilitate credential theft, lateral movement, persistent access, and data exfiltration. If left undetected, this activity can lead to a full system compromise, especially within environments utilizing untrusted machine learning model files or external packages.
Recommendation
Prioritized actions for detection engineering teams:
- Deploy the Sigma rule below to your macOS monitoring environment to identify anomalous shell spawning.
- Establish a baseline for normal Python execution behavior to tune the "first occurrence" detection logic.
- Implement environment-wide security controls for model loading, specifically enforcing
weights_only=Truefor all PyTorch model deployments. - Review and restrict the use of Python environments that allow arbitrary command execution in sensitive production segments.
- Update SIEM dashboards to alert on the first instance of process-parent-child execution chains where Python spawns
/bin/bashor/bin/zsh.
Immediate actions
Deploy the provided Sigma rule to production to baseline Python shell activity.
Threat Hunt
Search historical logs for any Python process spawning a shell in the last 30 days to identify potential existing persistence.
Data: Process creation logs
Detection coverage 1
Detect First Time Python Spawned a Shell on macOS
mediumDetects the first time a Python process spawns a shell with the -c flag on a macOS host, excluding common package management and data science tools.
Detection queries are available on the platform. Get full rules →