ZiChatBot Malicious PyPI Install Spawning Suspicious Child or Python Outbound
Detects potential supply chain attacks where a suspicious Python package is installed via 'pip' followed by execution of suspicious commands or network activity from 'python.exe' within a short timeframe. This rule correlates process creation events involving pip installations with subsequent suspicious command-line activity or external network connections from Python processes.
Splunk (SPL)

