This website uses cookies to ensure you get the best experience.
Got it!
Register
|
Login
Menu
Home
Sigma Rules
Splunk Rules
Explore Rules
Analytic Stories
MITRE ATT&CK
Overview
Matrix
Techniques
Groups
Software
Campaigns
Search
About
Potential Netcat Reverse Shell Execution
Original Source:
[Sigma source]
Title:
Potential Netcat Reverse Shell Execution
Status:
test
Description:
Detects execution of netcat with the "-e" or "-c" flags followed by common shells, which are commonly used to spawn reverse shells.
References:
-https://pentestmonkey.net/cheat-sheet/shells/reverse-shell-cheat-sheet
-https://www.revshells.com/
-https://www.hackingtutorials.org/networking/hacking-netcat-part-2-bind-reverse-shells/
-https://www.infosecademy.com/netcat-reverse-shells/
-https://man7.org/linux/man-pages/man1/ncat.1.html
Author:
@d4ns4n_, Nasreddine Bencherchali (Nextron Systems)
Date:
2023-04-07
modified:
2026-09-24
Tags:
-'attack.execution'
-'attack.t1059'
Logsource:
category: process_creation
product: linux
Detection:
selection_nc:
Image|endswith
:
-'/nc.openbsd'
-'/nc.traditional'
-'/nc'
-'/ncat'
-'/netcat.openbsd'
-'/netcat.traditional'
-'/netcat'
selection_flags:
CommandLine|contains
:
-' -c '
-' -e '
selection_shell:
CommandLine|contains
:
-' ash'
-' bash'
-' bsh'
-' csh'
-' ksh'
-' pdksh'
-' sh'
-' tcsh'
-'/bin/ash'
-'/bin/bash'
-'/bin/bsh'
-'/bin/csh'
-'/bin/ksh'
-'/bin/pdksh'
-'/bin/sh'
-'/bin/tcsh'
-'/bin/zsh'
-'$IFSash'
-'$IFSbash'
-'$IFSbsh'
-'$IFScsh'
-'$IFSksh'
-'$IFSpdksh'
-'$IFSsh'
-'$IFStcsh'
-'$IFSzsh'
condition
:
all of selection_*
Falsepositives:
-Unlikely
Level:
high