BIOC
Informational
✕
Netcat shell via named pipe
Attackers may create a Netcat shell using a named pipe to remotely access the endpoint.
- Module:
- Platform Analytics
- Agent event type:
- Process execution
- Category:
- Execution
- Status:
- Enabled
ATT&CK tactics: Execution (TA0002)
ATT&CK techniques: Command and Scripting Interpreter (T1059)
Indicator:
Process action type = execution AND target process name = mkfifo , mknod Process initiated by = *sh
Preventable: yes