This website uses cookies to ensure you get the best experience.
Got it!
Register
|
Login
Menu
Home
Sigma Rules
Splunk Rules
Explore Rules
Analytic Stories
MITRE ATT&CK
Overview
Matrix
Techniques
Groups
Software
Campaigns
Search
About
PUA - Netcat Suspicious Execution
Original Source:
[Sigma source]
Title:
PUA - Netcat Suspicious Execution
Status:
test
Description:
Detects execution of Netcat. Adversaries may use a non-application layer protocol for communication between host and C2 server or among infected hosts within a network
References:
-https://nmap.org/ncat/
-https://github.com/redcanaryco/atomic-red-team/blob/f339e7da7d05f6057fdfcdd3742bfcf365fee2a9/atomics/T1095/T1095.md
-https://www.revshells.com/
Author:
frack113, Florian Roth (Nextron Systems)
Date:
2021-07-21
modified:
2023-02-08
Tags:
-'attack.command-and-control'
-'attack.t1095'
Logsource:
category: process_creation
product: windows
Detection:
selection_img:
Image|endswith
:
-'\nc.exe'
-'\ncat.exe'
-'\netcat.exe'
selection_cmdline:
CommandLine|contains
:
-' -lvp '
-' -lvnp'
-' -l -v -p '
-' -lv -p '
-' -l --proxy-type http '
-' -vnl --exec '
-' -vnl -e '
-' --lua-exec '
-' --sh-exec '
condition
:
1 of selection_*
Falsepositives:
-Legitimate ncat use
Level:
high