Linux Reverse Shell Detection
This rule detects various methods of establishing a reverse shell on Linux systems. It looks for process creation events involving common shell interpreters (bash, sh) attempting to connect to network devices via /dev/tcp or /dev/udp. It also identifies the use of network utilities like netcat (nc, ncat, netcat, nc.traditional) and socat when used with command execution flags (-e, -c, EXEC) and shell interpreters. Additionally, it flags direct outbound network connections initiated by these shell interpreters or network utilities, which could indicate a reverse shell communication channel.
SentinelOne

