Linux netcat/ncat Execution with -e and Shell Invocation
Alerts on Linux executions of nc/ncat using -e that reference common shells, indicating potential reverse-shell setup.
- Product
- linux
- Category
- process_creation
- Author
- @d4ns4n_, Nasreddine Bencherchali (Nextron Systems) (SigmaHQ), DRL 1.1
- Published
- 2023-04-07
- Updated
- 2026-07-31
ATT&CK techniques
ExecutionRecon
Resource Dev
Initial Access
Persistence
Priv Esc
Defense Evasion
Cred Access
Discovery
Lateral Movement
Collection
C2
Exfiltration
Impact
What it detects
This rule flags Linux process creations where the executable path ends with '/nc' or '/ncat' and the command line contains the netcat-related flags '-c' and '-e'. It also requires the command line to include common shell interpreters (e.g., /bin/bash, /bin/sh, or shell names via $IFS*), which is consistent with spawning a shell through netcat. The detection relies on process creation telemetry with accurate Image and CommandLine fields.
Reporting behind it
- pentestmonkey.nethttps://pentestmonkey.net/cheat-sheet/shells/reverse-shell-cheat-sheet
- revshells.comhttps://www.revshells.com/
- hackingtutorials.orghttps://www.hackingtutorials.org/networking/hacking-netcat-part-2-bind-reverse-shells/
- infosecademy.comhttps://www.infosecademy.com/netcat-reverse-shells/
- man7.orghttps://man7.org/linux/man-pages/man1/ncat.1.html
- github.comhttps://github.com/SigmaHQ/sigma/blob/master/rules/linux/process_creation/proc_creation_lnx_netcat_reverse_shell.yml
Changelog
v2- v2Candidate ingested via manual entry.2026-07-31
- v1No changelog recorded for this version.2026-07-30
Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.
title: Linux netcat/ncat Execution with -e and Shell Invocation
id: 7be6f4b1-88be-417b-a4ad-cf2a5448cf0f
status: test
description: This rule flags Linux process creations where the executable path ends with '/nc' or '/ncat' and the command line contains the netcat-related flags '-c' and '-e'. It also requires the command line to include common shell interpreters (e.g., /bin/bash, /bin/sh, or shell names via $IFS*), which is consistent with spawning a shell through netcat. The detection relies on process creation telemetry with accurate Image and CommandLine fields.
references:
- https://pentestmonkey.net/cheat-sheet/shells/reverse-shell-cheat-sheet
- https://www.revshells.com/
- https://www.hackingtutorials.org/networking/hacking-netcat-part-2-bind-reverse-shells/
- https://www.infosecademy.com/netcat-reverse-shells/
- https://man7.org/linux/man-pages/man1/ncat.1.html
- https://github.com/SigmaHQ/sigma/blob/master/rules/linux/process_creation/proc_creation_lnx_netcat_reverse_shell.yml
author: "@d4ns4n_, Nasreddine Bencherchali (Nextron Systems), Huntrule Team"
date: 2023-04-07
tags:
- attack.execution
- attack.t1059
logsource:
category: process_creation
product: linux
detection:
selection_nc:
Image|endswith:
- /nc
- /ncat
selection_flags:
CommandLine|contains:
- " -c "
- " -e "
selection_shell:
CommandLine|contains:
- " ash"
- " bash"
- " bsh"
- " csh"
- " ksh"
- " pdksh"
- " sh"
- " tcsh"
- /bin/ash
- /bin/bash
- /bin/bsh
- /bin/csh
- /bin/ksh
- /bin/pdksh
- /bin/sh
- /bin/tcsh
- /bin/zsh
- $IFSash
- $IFSbash
- $IFSbsh
- $IFScsh
- $IFSksh
- $IFSpdksh
- $IFSsh
- $IFStcsh
- $IFSzsh
condition: all of selection_*
falsepositives:
- Unlikely
level: high
license: DRL-1.1
related:
- id: 7f734ed0-4f47-46c0-837f-6ee62505abd9
type: derived