Linux Process Execution of netcat/ncat With -e Followed by Shell Invocation

Alerts on Linux executions of nc/ncat using -e that reference common shells, indicating potential reverse-shell setup.

FreeUnreviewedSigmahighv1
title: Linux Process Execution of netcat/ncat With -e Followed by Shell Invocation
id: 7be6f4b1-88be-417b-a4ad-cf2a5448cf0f
status: test
description: This rule flags Linux process creation events where the executable name ends with /nc or /ncat and the command line includes the -e option and shell-related arguments. Using netcat with -e to spawn a local shell is commonly associated with reverse-shell or command execution workflows, so identifying it can help detect attacker-controlled interactive access. It relies on process creation telemetry that includes the executed binary path/name and the full command line.
references:
  - https://pentestmonkey.net/cheat-sheet/shells/reverse-shell-cheat-sheet
  - https://www.revshells.com/
  - https://www.hackingtutorials.org/networking/hacking-netcat-part-2-bind-reverse-shells/
  - https://www.infosecademy.com/netcat-reverse-shells/
  - https://man7.org/linux/man-pages/man1/ncat.1.html
  - https://github.com/SigmaHQ/sigma/blob/master/rules/linux/process_creation/proc_creation_lnx_netcat_reverse_shell.yml
author: "@d4ns4n_, Nasreddine Bencherchali (Nextron Systems), Huntrule Team"
date: 2023-04-07
tags:
  - attack.execution
  - attack.t1059
logsource:
  category: process_creation
  product: linux
detection:
  selection_nc:
    Image|endswith:
      - /nc
      - /ncat
  selection_flags:
    CommandLine|contains:
      - " -c "
      - " -e "
  selection_shell:
    CommandLine|contains:
      - " ash"
      - " bash"
      - " bsh"
      - " csh"
      - " ksh"
      - " pdksh"
      - " sh"
      - " tcsh"
      - /bin/ash
      - /bin/bash
      - /bin/bsh
      - /bin/csh
      - /bin/ksh
      - /bin/pdksh
      - /bin/sh
      - /bin/tcsh
      - /bin/zsh
      - $IFSash
      - $IFSbash
      - $IFSbsh
      - $IFScsh
      - $IFSksh
      - $IFSpdksh
      - $IFSsh
      - $IFStcsh
      - $IFSzsh
  condition: all of selection_*
falsepositives:
  - Unlikely
level: high
license: DRL-1.1
related:
  - id: 7f734ed0-4f47-46c0-837f-6ee62505abd9
    type: derived

What it detects

This rule flags Linux process creation events where the executable name ends with /nc or /ncat and the command line includes the -e option and shell-related arguments. Using netcat with -e to spawn a local shell is commonly associated with reverse-shell or command execution workflows, so identifying it can help detect attacker-controlled interactive access. It relies on process creation telemetry that includes the executed binary path/name and the full command line.

Known false positives

  • Unlikely

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.