From c801be9f3dccde4e1d6f0eae47da5baba62814f6 Mon Sep 17 00:00:00 2001 From: HueCodes <197298026+HueCodes@users.noreply.github.com> Date: Thu, 23 Apr 2026 05:37:28 -0700 Subject: [PATCH] Merge PR #5899 from @HueCodes - new: Python Base64 Encoded Inline Command Execution new: Python Base64 Encoded Inline Command Execution - Windows new: Python Base64 Encoded Inline Command Execution - Linux --------- Co-authored-by: Hugh Co-authored-by: Swachchhanda Shrawan Poudel <87493836+swachchhanda000@users.noreply.github.com> Co-authored-by: phantinuss <79651203+phantinuss@users.noreply.github.com> --- .../50a0aa3d-ab16-4594-a8aa-5145a6e6792b.evtx | Bin 0 -> 69632 bytes .../50a0aa3d-ab16-4594-a8aa-5145a6e6792b.json | 66 ++++++++++++++++++ .../info.yml | 13 ++++ ...on_lnx_python_base64_encoded_execution.yml | 43 ++++++++++++ ...on_win_python_base64_encoded_execution.yml | 45 ++++++++++++ 5 files changed, 167 insertions(+) create mode 100644 regression_data/rules/windows/process_creation/proc_creation_win_python_base64_encoded_execution/50a0aa3d-ab16-4594-a8aa-5145a6e6792b.evtx create mode 100644 regression_data/rules/windows/process_creation/proc_creation_win_python_base64_encoded_execution/50a0aa3d-ab16-4594-a8aa-5145a6e6792b.json create mode 100644 regression_data/rules/windows/process_creation/proc_creation_win_python_base64_encoded_execution/info.yml create mode 100644 rules/linux/process_creation/proc_creation_lnx_python_base64_encoded_execution.yml create mode 100644 rules/windows/process_creation/proc_creation_win_python_base64_encoded_execution.yml diff --git a/regression_data/rules/windows/process_creation/proc_creation_win_python_base64_encoded_execution/50a0aa3d-ab16-4594-a8aa-5145a6e6792b.evtx b/regression_data/rules/windows/process_creation/proc_creation_win_python_base64_encoded_execution/50a0aa3d-ab16-4594-a8aa-5145a6e6792b.evtx new file mode 100644 index 0000000000000000000000000000000000000000..b3cd3c0321b804c165361524eea663ade554aa40 GIT binary patch literal 69632 zcmeI0TWnlc6^7S2o*9qFp0VA;T$|vy1(Hxte81EQl|A<4W{1!Vy~xONe2LxoMr^ln zgHTkcs`3D>D#Sw{K&TQFA>N80LP7$eikDVGm4FH=5HE#?qJSzu1)2Zf`y9{M_>$5W zK>rz?Is3Bq+G~G%t+mh0(A;!!c5ceHUSZU54bRXj%<6)zBJaB1|M#~){;risfe46z z2#A0Ph=2%)fCz|y2#A0Ph`^o%hUTUVGYgk2{&m08^BOhbPl2UC&>r4%rPJ7;@B6W@(5&$(0P4}9?IP8_4~?_}kDi z?Ehzfb2jtPPktTL27%QCulK$At#~Gu5C7r0yPJOZ%U7?xQ2))Ru@Xx4*V`9R{0YB;Mry^_;jGuVmpNhn0L23bgVXoQ|3B=q%RALvOd^u^u5aeFXIU%D^ zXt$zrYviXxR}*%x+lxz1B;#DJR6^UHE9ZJ|O5QXcx8=i^- z%daAB4VE^fIa~>pc&9DnS5!E14;L^8VcEm7e&>V7YptZ!9?T)Jy-o@7w!d$A(b~d-!t{dFt{Se4GvzC+|V0 zb{y@@i@kXA6sDhjaWR2h#Yx%we%vYM!(@<#Z?D3Fsg0Z%X0avQ=nqHZ-&>Nd#8$3= zSRA%t78X&qIg)i-?=@F%aq2j+hS|_+Ip#<-=7S~u{~idF7G^6fP5DESJa<2`J_(oN z!E+JzhgrDMjaE-UdfkrX|9*l8g#1QdyFJ7dAc zG;=853kETUWv+@TnD$ot(cE+T8KX6_H?a}&VYbFgZM)mU&~?#8R>?b%MrqTw-dB=8 zjdg_CoIi?UPyblSf_nHU4*-B?` zm}NeNmA6GB8%iTnNJxAY;!DvoY^?W^+uC>@k}+ZLIq?xt;&F@T(HYI;j#D3DwTQ5t z#{2c{^XuCoI!j~AqiFw4+PjlaHTdz|3wp(Y5}C{$WB9-T(w9b_O zILh#!jk^P7*k{woga`4w9XF2v9v76S>{0ZwjrG@1e>0M6cCVdnco}SVFQ5Eww?=El z=T4Nn@y!?0JnC(DEj@VKSA&_ay)yf~N*HEYJB}3l zXS4U*2I1mDTz{w2(~H`GYxVYZyV$>o*ncsK{pXS2eeC-z%`<_&AQ?;ky@I)5 z^P8j325c{n&8^Y6T`cA|jTpg9Ji+*mbJ@ngrOV}sJW3r{XCC($asz#Q44==y;~oQ- z1@vFSFHlYKmYKmYKmYKmYKmY zKmYKmYKmYKmYKmYKmYKmYKmYKmYKmYKmYKmYKmY zKmYKmYKmYKmYKmYKmYKmYKmYKmYKmYKm