Tag
high
advisory
Detection of Oversized Base64 Obfuscated Interpreter Commands
1 rule 3 TTPsAdversaries leverage oversized, base64-encoded command lines in scripting interpreters to evade security telemetry that truncates or ignores excessively large command-line arguments.
defense-evasion
execution
command-line-obfuscation
scripting-interpreter
1r
3t
high
advisory
Long Base64 Encoded Command via Scripting Interpreter
2 rules 5 TTPsDetection of oversized command lines used by Python, PowerShell, Node.js, or Deno interpreters containing base64 decoding or encoded-command patterns, indicating potential evasion and malicious execution.
Elastic Endpoint
defense-evasion
execution
scripting-interpreter
base64
command-line
2r
5t