Cross-source coverage

T1059.011 / ATT&CK

Command and Scripting Interpreter: Lua

15 rules across 2 sources.

Showing deprecated rules · back to the default

From MITRE ATT&CK 19.2

Adversaries may abuse Lua commands and scripts for execution. Lua is a cross-platform scripting and programming language primarily designed for embedded use in applications. Lua can be executed on the command-line (through the stand-alone lua interpreter), via scripts (.lua), or from Lua-embedded programs (through the struct lua_State).

Lua scripts may be executed by adversaries for malicious purposes. Adversaries may incorporate, abuse, or replace existing Lua interpreters to allow for malicious Lua command execution at runtime.

Tactics
Execution
Platforms
Linux · Network Devices · Windows · macOS
Telemetry
WinEventLog:Sysmonauditd:SYSCALLmacos:unifiedlognetworkdevice:runtime

How MITRE says to detect it DET0101

Detection Strategy for Lua Scripting Abuse

Windows Analytic 0278

Detects execution of Lua interpreters or scripts (.lua), especially when correlated with suspicious parent processes or file drop events, indicating malicious use of embedded scripting.

  • WinEventLog:Sysmon EventCode=1
  • WinEventLog:Sysmon EventCode=11

Linux Analytic 0279

Detects invocation of lua or luajit interpreters by users or services outside of expected packages, chained with script drop or memory artifacts.

  • auditd:SYSCALL execve
  • auditd:SYSCALL PATH

macOS Analytic 0280

Detects Lua script execution via native or 3rd party interpreters, chained with unsigned binaries or unexpected parent lineage.

  • macos:unifiedlog log stream

Network Devices Analytic 0281

Detects embedded Lua interpreter execution or script injection on devices supporting Lua scripting (e.g., routers, firewalls), often seen in modified firmware or abused APIs.

  • networkdevice:runtime runtime

elastic/detection-rules

10 rules
Detection Severity Format
Potential Redis Lua Use-After-Free RCE Attempt (CVE-2025-49844 / RediShell) Critical Elastic TOML
Base64 Decoded Payload Piped to Interpreter High Elastic TOML
Decoded Payload Piped to Interpreter Detected via Defend for Containers High Elastic TOML
Process Spawned from Message-of-the-Day (MOTD) High Elastic TOML
Suspicious React Server Child Process High Elastic TOML
Potential Reverse Shell via UDP Medium Elastic TOML
Suspicious Interpreter Execution Detected via Defend for Containers Medium Elastic TOML
Deprecated - Unusual Process Spawned from Web Server Parent Low Elastic TOML
Potential Hex Payload Execution via Common Utility Low Elastic TOML
Web Server Potential Command Injection Request Low Elastic TOML

elastic/protections-artifacts

5 rules
Detection Severity Format
Command Interpreter with IP Address Argument Undefined Elastic TOML
Long Base64 Command Execution via Interactive Shell Undefined Elastic TOML
Long Base64 Encoded Interpreter Command Line Undefined Elastic TOML
Potential Fileless Execution via Memory File Descriptor from Interpreter Undefined Elastic TOML
Suspicious Lua Command Execution Undefined Elastic TOML

Detection rules belong to the projects that publish them and remain under their own licenses. This site indexes and links to them; it claims no rights in them.