Analytics Alerts
Browse the Cortex analytics alert reference.
1 alert match the current filters. tactic: TA0002 ✕ technique: T1059 ✕
Download CSV Show ATT&CK heatmapA TCP stream was created directly in a shell Medium
Attackers may create a TCP stream using the shell command line to generate a reverse shell, enabling remote access to the endpoint.
- Activation:
- 14 Days
- Training:
- 30 Days
- Test:
- N/A (single event)
- Deduplication:
- 1 Day
ATT&CK tactics: Execution (TA0002)ATT&CK techniques: Command and Scripting Interpreter (T1059)Required data: XDR AgentAttacker's goals: Attackers may use this device file to create sockets though shell commands as part of a reverse shell.Investigative actions: Review the command line used. Search for the corresponding network event. Check the prevalence of the target IP/domain.