Capsh Shell Invocation - Linux

Rule Info

Name
Capsh Shell Invocation - Linux
Author
Li Ling, Andy Parkidomo, Robert Rakowski, Blake Hartstein (Bloomberg L.P.)
Description
Detects the use of the "capsh" utility to invoke a shell.
Date
2024-09-02 00:00:00
Modified
None
Id
db1ac3be-f606-4e3a-89e0-9607cbe6b98a
Tags
attack.execution attack.t1059 DEMO
Type
Community Rule

Rule History

Author
Title
Date
Commit
Murphy0801
Merge PR #4975 from @Murphy0801 - Add new rules related to GTFOBins
2024-09-02