Shell Execution GCC - Linux

Rule Info

Name
Shell Execution GCC - Linux
Author
Li Ling, Andy Parkidomo, Robert Rakowski, Blake Hartstein (Bloomberg L.P.)
Description
Detects the use of the "gcc" utility to execute a shell. Such behavior may be associated with privilege escalation, unauthorized command execution, or to break out from restricted environments.
Date
2024-09-02 00:00:00
Modified
None
Id
9b5de532-a757-4d70-946c-1f3e44f48b4d
Tags
attack.discovery attack.t1083
Type
Community Rule

Rule History

Author
Title
Date
Commit
Murphy0801
Merge PR #4975 from @Murphy0801 - Add new rules related to GTFOBins
2024-09-02