A TCP stream was created directly in a shell

Cortex XDR Analytics Alert Reference by data source

Product
Cortex XDR
Last date published
2024-12-03
Category
Analytics Alert Reference
Order
data source

Synopsis

Activation Period

14 Days

Training Period

30 Days

Test Period

N/A (single event)

Deduplication Period

1 Day

Required Data

  • Requires:
    • XDR Agent

Detection Modules

Detector Tags

ATT&CK Tactic

Execution (TA0002)

ATT&CK Technique

Command and Scripting Interpreter (T1059)

Severity

Medium

Description

Attackers may create a TCP stream using the shell command line to generate a reverse shell, enabling remote access to the endpoint.

Attacker's Goals

Attackers may use this device file to create sockets though shell commands as part of a reverse shell.

Investigative actions

  • Review the command line used.
  • Search for the corresponding network event.
  • Check the prevalence of the target IP/domain.