1200KM / detection
T1059.011 Lua — Detection Rules
Detection workspace for T1059.011 Lua: 0 Sigma sources, 0 Atlas concepts and 0 anomaly models. No live detection validation.
Source-backed rule directory
No reviewed association in this snapshot.
Atlas deterministic concepts
No exact concept selected.
Anomaly models
No exact Atlas model in this snapshot.
ATT&CK analytic guidance
DET0101 Detection Strategy for Lua Scripting Abuse
AN0278 Analytic 0278
Detects execution of Lua interpreters or scripts (.lua), especially when correlated with suspicious parent processes or file drop events, indicating malicious use of embedded scripting.
AN0279 Analytic 0279
Detects invocation of lua or luajit interpreters by users or services outside of expected packages, chained with script drop or memory artifacts.
AN0280 Analytic 0280
Detects Lua script execution via native or 3rd party interpreters, chained with unsigned binaries or unexpected parent lineage.
AN0281 Analytic 0281
Detects embedded Lua interpreter execution or script injection on devices supporting Lua scripting (e.g., routers, firewalls), often seen in modified firmware or abused APIs.
Connected ecosystem references
Linked tags
Simulation, tools and telemetry
T1059.011 simulation workspace
- Command Execution · DC0064
- File Creation · DC0039
- File Metadata · DC0059
- Process Creation · DC0032
- Script Execution · DC0029
No reviewed association in this snapshot.
Existing anomaly research
Pinned research references. No browser attack runner, live simulation result or validated detector is asserted. Source mappings and validation limits are preserved. ATT&CK / Atomic provenance · Detection provenance.