Tag
medium
advisory
Detection of Malicious Netcat Usage on Linux
1 rule 1 TTPThis brief details the detection of suspicious outbound network connections initiated by Netcat (nc, ncat) utilities on Linux systems, which are frequently used by threat actors for C2 communication and data exfiltration.
Splunk Enterprise +2
linux
netcat
command-and-control
exfiltration
post-exploitation
1r
1t
medium
advisory
Netcat Listener or File Transfer Detected in Containers
1 rule 3 TTPsThis threat brief details the detection of malicious Netcat usage within Linux containers, indicating potential backdoor establishment, persistence, command and control, or data exfiltration by adversaries.
Containers
container
linux
execution
command-and-control
exfiltration
netcat
1r
3t
high
advisory
Potential Command Shell via NetCat Execution
2 rules 3 TTPsThe rule identifies potential attempts to execute a reverse shell using the netcat utility to execute Windows commands via Cmd.exe or Powershell.
Elastic Defend
reverse shell
netcat
command execution
windows
2r
3t