Skip to content

Update proc_creation_lnx_env_shell_invocation.yml so that it covers all the examples given in the referenced link#5828

Open
Zirbo wants to merge 3 commits intoSigmaHQ:masterfrom
Zirbo:master
Open

Update proc_creation_lnx_env_shell_invocation.yml so that it covers all the examples given in the referenced link#5828
Zirbo wants to merge 3 commits intoSigmaHQ:masterfrom
Zirbo:master

Conversation

@Zirbo
Copy link

@Zirbo Zirbo commented Jan 8, 2026

Summary of the Pull Request

Update proc_creation_lnx_env_shell_invocation.yml so that it covers all the examples given in the referenced link
Switched endswith with contains to account for invocations like: ./env /bin/sh -p
as in the example given in the first reference: https://gtfobins.github.io/gtfobins/env/#shell

Changelog

modified: Shell Invocation via Env Command - Linux - fix detection block

Example Log Event

Fixed Issues

SigmaHQ Rule Creation Conventions

  • If your PR adds new rules, please consider following and applying these conventions

switched endswith with contains to account for invocations like:
./env /bin/sh -p
as in the examples in https://gtfobins.github.io/gtfobins/env/#shell
@github-actions github-actions bot added Rules Review Needed The PR requires review Linux Pull request add/update linux related rules labels Jan 8, 2026
Zirbo and others added 2 commits January 8, 2026 19:05
…ation.yml

Co-authored-by: Swachchhanda Shrawan Poudel <87493836+swachchhanda000@users.noreply.github.com>
…ation.yml

Co-authored-by: Swachchhanda Shrawan Poudel <87493836+swachchhanda000@users.noreply.github.com>
@swachchhanda000 swachchhanda000 added this to the Sigma-February-Release milestone Feb 6, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Linux Pull request add/update linux related rules Review Needed The PR requires review Rules

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants