Linux Process Execution of netcat/ncat With -e Followed by Shell Invocation
Alerts on Linux executions of nc/ncat using -e that reference common shells, indicating potential reverse-shell setup.
FreeUnreviewedSigmahighv1
linux-process-execution-of-netcat-ncat-with-e-followed-by-shell-invocation-7f734ed0
title: Linux Process Execution of netcat/ncat With -e Followed by Shell Invocation
id: 7be6f4b1-88be-417b-a4ad-cf2a5448cf0f
status: test
description: This rule flags Linux process creation events where the executable name ends with /nc or /ncat and the command line includes the -e option and shell-related arguments. Using netcat with -e to spawn a local shell is commonly associated with reverse-shell or command execution workflows, so identifying it can help detect attacker-controlled interactive access. It relies on process creation telemetry that includes the executed binary path/name and the full command line.
references:
- https://pentestmonkey.net/cheat-sheet/shells/reverse-shell-cheat-sheet
- https://www.revshells.com/
- https://www.hackingtutorials.org/networking/hacking-netcat-part-2-bind-reverse-shells/
- https://www.infosecademy.com/netcat-reverse-shells/
- https://man7.org/linux/man-pages/man1/ncat.1.html
- https://github.com/SigmaHQ/sigma/blob/master/rules/linux/process_creation/proc_creation_lnx_netcat_reverse_shell.yml
author: "@d4ns4n_, Nasreddine Bencherchali (Nextron Systems), Huntrule Team"
date: 2023-04-07
tags:
- attack.execution
- attack.t1059
logsource:
category: process_creation
product: linux
detection:
selection_nc:
Image|endswith:
- /nc
- /ncat
selection_flags:
CommandLine|contains:
- " -c "
- " -e "
selection_shell:
CommandLine|contains:
- " ash"
- " bash"
- " bsh"
- " csh"
- " ksh"
- " pdksh"
- " sh"
- " tcsh"
- /bin/ash
- /bin/bash
- /bin/bsh
- /bin/csh
- /bin/ksh
- /bin/pdksh
- /bin/sh
- /bin/tcsh
- /bin/zsh
- $IFSash
- $IFSbash
- $IFSbsh
- $IFScsh
- $IFSksh
- $IFSpdksh
- $IFSsh
- $IFStcsh
- $IFSzsh
condition: all of selection_*
falsepositives:
- Unlikely
level: high
license: DRL-1.1
related:
- id: 7f734ed0-4f47-46c0-837f-6ee62505abd9
type: derived
What it detects
This rule flags Linux process creation events where the executable name ends with /nc or /ncat and the command line includes the -e option and shell-related arguments. Using netcat with -e to spawn a local shell is commonly associated with reverse-shell or command execution workflows, so identifying it can help detect attacker-controlled interactive access. It relies on process creation telemetry that includes the executed binary path/name and the full command line.
Known false positives
- Unlikely
Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.