Write-Then-Execute Script in Temporary Directory (EDR Graph)
This detects a common malware pattern: a program drops a script file into a temporary directory like /tmp or /dev/shm and then executes it right away. Legitimate software rarely needs to write and run scripts from these locations, so this sequence is a strong sign of an attack in progress.
How the attack works
An agent or process first writes a script file into /tmp, /var/tmp, or /dev/shm — directories that are usually world-writable and not meant for storing executable code. The same agent then spawns a process to run that script. The detection watches for a process launch and checks that a matching file-write to that path happened just before it, so the write-then-run pattern is confirmed at the moment of execution rather than after the fact.
Netzilo detection
Netzilo reports this behaviour when it is observed.
- Signature ID
- 2564f91e-155e-5d1c-afda-718922bb8a5f-p
- Severity
- High
Why it matters
This behavior lets an attacker stage and run arbitrary code without dropping it in a normal application directory, often to execute payloads, establish persistence, or run second-stage tools while avoiding disk locations that get more scrutiny.
What you can do
- →Mount /tmp, /var/tmp, and /dev/shm with noexec where your workloads allow it, so scripts placed there cannot be executed directly.
- →Review any process that writes a file to these directories and then executes it, especially if the process is an automation agent or service account.
- →Restrict which accounts and services can write to shared temp directories.
- →Alert on and investigate any script interpreter (shell, python, perl, etc.) invoked directly from a temp path.