Tag
medium
advisory
Suspicious Python Shell Command Execution
1 rule 1 TTPThis detection logic identifies potentially malicious activity where a Python process rapidly spawns multiple shell commands via '-c' arguments for host profiling, discovery, or lateral movement.
execution
script-based-execution
python
linux
macos
1r
1t
medium
advisory
Detection of ROT-Encoded Python Script Execution
1 rule 3 TTPsAdversaries utilize ROT-encoded Python scripts within packages to obfuscate malicious logic and evade security analysis on Windows and macOS systems.
defense-evasion
python
script-based-execution
obfuscation
1r
3t