Rule Info
Name
Shell Execution via Flock - Linux
Author
Li Ling, Andy Parkidomo, Robert Rakowski, Blake Hartstein (Bloomberg L.P.)
Description
Detects the use of the "flock" command to execute a shell. Such behavior may be associated with privilege escalation, unauthorized command execution, or to break out from restricted environments.
Date
2024-09-02 00:00:00
Modified
None
Id
4b09c71e-4269-4111-9cdd-107d8867f0cc
Tags
attack.discovery attack.t1083 DEMO
Type
Community Rule
Link to Public Repo
Rule History
Author
Title
Date
Commit