Suspicious Reverse Shell via Dev TCP or Netcat

PremiumReviewedSigma · High · v1
Product
linux
Category
process_creation
Author
HuntRule
Published
2026-09-13
Updated
2026-09-13

ATT&CK techniques

Execution → C2
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Persistence

  5. Priv Esc

  6. Defense Evasion

  7. Cred Access

  8. Discovery

  9. Lateral Movement

  10. Collection

  11. Exfiltration

  12. Impact

What it detects

This rule detects Linux reverse-shell construction using bash /dev/tcp redirection or netcat with command execution, techniques used to obtain remote access after ActiveMQ CVE-2023-46604 exploitation. Attackers open these outbound shells to control the compromised broker interactively. These reverse-shell patterns are hallmark hands-on-keyboard command-and-control indicators.

Related detections9 linkedT1071.001 — drag to rearrange
Malicious Bash Dev-TCP Reverse Shell via Shell (via process_creation)
Malicious Named Pipe Netcat Reverse Shell via Shell (via process_creation)
Suspicious Base64 Decoded Payload Piped to Shell
Suspicious Shell Spawned by ActiveMQ Java Process
Malicious HarborWatch RAT Command and Control Beacon by User Agent (via proxy)
Suspicious UAT-10608 Credential Harvesting C2 Beacon via HTTP
Malicious BadIIS C2 Communication via lwxatisme User-Agent
Possible PS1Bot C2 Beacon With Drive Serial URI Pattern (via proxy)
Suspicious WarmCookie C2 Beacon With Fixed Firefox User-Agent
Suspicious Reverse Shell via Dev TCP or Netcat
Pivot detection · T1071.001 · 9 related

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.