BIOC
Informational
✕
Shell binary copied to another location
Attackers may try to evade detection by copying the shell binary to an innocent-looking name.
- Module:
- Platform Analytics
- Agent event type:
- Process execution
- Category:
- Tampering
- Status:
- Enabled
ATT&CK tactics: Defense Evasion (TA0005)
ATT&CK techniques: Masquerading (T1036)
Indicator:
Process action type = execution AND target process cmd =~ /bin/(ba|z|fi|tc|c|k)?sh AND target process name = cp
Preventable: yes