Cross-source coverage
T1059.011 / ATT&CK
Command and Scripting Interpreter: Lua
14 rules across 2 sources.
1 deprecated hidden · include
From MITRE ATT&CK 19.2
Adversaries may abuse Lua commands and scripts for execution. Lua is a cross-platform scripting and programming language primarily designed for embedded use in applications. Lua can be executed on the command-line (through the stand-alone lua interpreter), via scripts (.lua), or from Lua-embedded programs (through the struct lua_State).
Lua scripts may be executed by adversaries for malicious purposes. Adversaries may incorporate, abuse, or replace existing Lua interpreters to allow for malicious Lua command execution at runtime.
- Tactics
- Execution
- Platforms
- Linux · Network Devices · Windows · macOS
- Telemetry
-
WinEventLog:Sysmonauditd:SYSCALLmacos:unifiedlognetworkdevice:runtime
How MITRE says to detect it DET0101
Detection Strategy for Lua Scripting Abuse
Windows Analytic 0278
Detects execution of Lua interpreters or scripts (.lua), especially when correlated with suspicious parent processes or file drop events, indicating malicious use of embedded scripting.
WinEventLog:SysmonEventCode=1WinEventLog:SysmonEventCode=11
Linux Analytic 0279
Detects invocation of lua or luajit interpreters by users or services outside of expected packages, chained with script drop or memory artifacts.
auditd:SYSCALLexecveauditd:SYSCALLPATH
macOS Analytic 0280
Detects Lua script execution via native or 3rd party interpreters, chained with unsigned binaries or unexpected parent lineage.
macos:unifiedloglog stream
Network Devices Analytic 0281
Detects embedded Lua interpreter execution or script injection on devices supporting Lua scripting (e.g., routers, firewalls), often seen in modified firmware or abused APIs.
networkdevice:runtimeruntime
elastic/detection-rules
9 rules| Detection | Severity | Format |
|---|---|---|
| Potential Redis Lua Use-After-Free RCE Attempt (CVE-2025-49844 / RediShell) | Critical | Elastic TOML |
| Base64 Decoded Payload Piped to Interpreter | High | Elastic TOML |
| Decoded Payload Piped to Interpreter Detected via Defend for Containers | High | Elastic TOML |
| Process Spawned from Message-of-the-Day (MOTD) | High | Elastic TOML |
| Suspicious React Server Child Process | High | Elastic TOML |
| Potential Reverse Shell via UDP | Medium | Elastic TOML |
| Suspicious Interpreter Execution Detected via Defend for Containers | Medium | Elastic TOML |
| Potential Hex Payload Execution via Common Utility | Low | Elastic TOML |
| Web Server Potential Command Injection Request | Low | Elastic TOML |
elastic/protections-artifacts
5 rules| Detection | Severity | Format |
|---|---|---|
| Command Interpreter with IP Address Argument | Undefined | Elastic TOML |
| Long Base64 Command Execution via Interactive Shell | Undefined | Elastic TOML |
| Long Base64 Encoded Interpreter Command Line | Undefined | Elastic TOML |
| Potential Fileless Execution via Memory File Descriptor from Interpreter | Undefined | Elastic TOML |
| Suspicious Lua Command Execution | Undefined | Elastic TOML |