{"id":"T1059.011","name":"Lua","url":"https://attack.mitre.org/techniques/T1059/011","tactics":["execution"],"platforms":["Linux","Network Devices","Windows","macOS"],"live":true,"revoked":false,"deprecated":false,"revoked_by":null,"detection_strategies":[{"id":"DET0101","stix_id":"x-mitre-detection-strategy--be7a4dda-a46a-4245-8837-e69946a79d3f","name":"Detection Strategy for Lua Scripting Abuse","url":"https://attack.mitre.org/detectionstrategies/DET0101","analytics":[{"id":"AN0278","stix_id":"x-mitre-analytic--b3ea7945-a7ef-421c-be84-af86b2b95ae5","name":"Analytic 0278","description":"Detects execution of Lua interpreters or scripts (.lua), especially when correlated with suspicious parent processes or file drop events, indicating malicious use of embedded scripting.","url":"https://attack.mitre.org/detectionstrategies/DET0101#AN0278","platforms":["Windows"],"log_source_references":[{"name":"WinEventLog:Sysmon","channel":"EventCode=1","data_component":"DC0032","data_component_name":"Process Creation","log_source_slug":"wineventlog-sysmon"},{"name":"WinEventLog:Sysmon","channel":"EventCode=11","data_component":"DC0039","data_component_name":"File Creation","log_source_slug":"wineventlog-sysmon"}],"mutable_elements":[{"field":"ParentProcessName","description":"May vary depending on delivery vector (e.g., explorer.exe, cmd.exe, rundll32.exe)"},{"field":"TimeWindow","description":"Used to correlate file drop and execution of Lua scripts in close succession."}],"live":true,"detection_strategies":["DET0101"],"techniques":["T1059.011"]},{"id":"AN0279","stix_id":"x-mitre-analytic--f8e77c9a-2b8c-47d2-b44a-23857d246016","name":"Analytic 0279","description":"Detects invocation of lua or luajit interpreters by users or services outside of expected packages, chained with script drop or memory artifacts.","url":"https://attack.mitre.org/detectionstrategies/DET0101#AN0279","platforms":["Linux"],"log_source_references":[{"name":"auditd:SYSCALL","channel":"execve","data_component":"DC0032","data_component_name":"Process Creation","log_source_slug":"auditd-syscall"},{"name":"auditd:SYSCALL","channel":"PATH","data_component":"DC0059","data_component_name":"File Metadata","log_source_slug":"auditd-syscall"}],"mutable_elements":[{"field":"ExecutablePath","description":"Lua interpreter path may vary based on distro or adversary staging."},{"field":"UserContext","description":"May need to exclude service or admin accounts that use Lua legitimately."}],"live":true,"detection_strategies":["DET0101"],"techniques":["T1059.011"]},{"id":"AN0280","stix_id":"x-mitre-analytic--4b53b71f-16b4-483b-b64a-eacf6c9db077","name":"Analytic 0280","description":"Detects Lua script execution via native or 3rd party interpreters, chained with unsigned binaries or unexpected parent lineage.","url":"https://attack.mitre.org/detectionstrategies/DET0101#AN0280","platforms":["macOS"],"log_source_references":[{"name":"macos:unifiedlog","channel":"log stream","data_component":"DC0064","data_component_name":"Command Execution","log_source_slug":"macos-unifiedlog"}],"mutable_elements":[{"field":"ParentProcessName","description":"Adjustable based on system activity patterns (e.g., Terminal vs GUI)"},{"field":"SignatureStatus","description":"Helps filter unsigned or self-signed Lua payloads."}],"live":true,"detection_strategies":["DET0101"],"techniques":["T1059.011"]},{"id":"AN0281","stix_id":"x-mitre-analytic--755fb4b5-903f-4694-b591-04078afa27aa","name":"Analytic 0281","description":"Detects embedded Lua interpreter execution or script injection on devices supporting Lua scripting (e.g., routers, firewalls), often seen in modified firmware or abused APIs.","url":"https://attack.mitre.org/detectionstrategies/DET0101#AN0281","platforms":["Network Devices"],"log_source_references":[{"name":"networkdevice:runtime","channel":"runtime","data_component":"DC0029","data_component_name":"Script Execution","log_source_slug":"networkdevice-runtime"}],"mutable_elements":[{"field":"FirmwareBuildHash","description":"Used to baseline known good versions versus injected scripts."},{"field":"ScriptInjectionPath","description":"Path to where scripts are allowed or denied based on config."}],"live":true,"detection_strategies":["DET0101"],"techniques":["T1059.011"]}],"live":true,"version":"1.0","techniques":["T1059.011"]}],"sigma_rules":[],"kev_cves":[],"_built":"2026-08-24 19:45 UTC","_attack_version":"19.2","_sigma_commit":"da9bb07d642a2826e89702445d32c795209ec108"}