BIOC Informational

Netcat shell via named pipe

Attackers may create a Netcat shell using a named pipe to remotely access the endpoint.

Module:
Platform Analytics
Agent event type:
Process execution
Category:
Execution
Status:
Enabled
ATT&CK tactics: Execution (TA0002)
ATT&CK techniques: Command and Scripting Interpreter (T1059)
Indicator:

Process action type = execution AND target process name = mkfifo , mknod Process initiated by = *sh

Preventable: yes