BIOC
Medium
✕
PowerShell reverse shell
This rule looks for a PowerShell instance that is communicating over known Metasploit ports back to an attacker in cases of reverse shell.
- Module:
- Platform Analytics
- Agent event type:
- Network
- Category:
- Execution
- Status:
- Enabled
ATT&CK tactics: Execution (TA0002)
ATT&CK techniques: Command and Scripting Interpreter: PowerShell (T1059.001)
Indicator:
Network action type = outgoing , failed AND remote port = 4444 Process initiator cmd = *web*downloadstring*.ps1* , *web*downloadstring*.exe* AND initiated by = powershell.exe
Preventable: yes