Analytics BIOC High

Netcat makes or gets connections

Malicious actors can use Netcat for privilege escalation, remote code execution, data exfiltration and protocol tunneling to evade detection.

Module:
Platform Analytics
Data source:
XDR Agent
ATT&CK tactics: Command and Control (TA0011)
ATT&CK techniques: Proxy: Multi-hop Proxy (T1090.003)
Attacker's goals:

Establish command and control channel. Propagate in the victim network.

Investigative actions:

Verify that the usage of Netcat/Netcat64 is from an authorized personnel and that user has the right to access the remote host.

Test period:
N/A (single event)
Deduplication:
1 Day