LetsDefend Monitoring Alert

Possible Reverse Shell Detected

Mar, 21, 2024, 07:28 AM

Event ID: 241

Event Time: Mar, 21, 2024, 07:28 AM

Rule Name: SOC194 - Possible Reverse Shell Detected

Alert Type: C2

MITRE Technique:
T1053.003 - Persistence - Scheduled Task/Job: Cron,
T1110 - Credential Access - Brute Force,
T1133 - Initial Access - External Remote Services,
T1098 - Persistence - Account Manipulation,
T1571 - Command and Control - Non-Standard Port,
T1059.004 - Execution - Command and Scripting Interpreter: Unix Shell,

Severity: Medium

Incident Responder

2025 © LetsDefend

45305 Catalina ct. Suite 150, Sterling VA 20166