1200KM / detection
T1059.004 Unix Shell — Detection Rules
Detection workspace for T1059.004 Unix Shell: 15 Sigma sources, 1 Atlas concepts and 0 anomaly models. No live detection validation.
Source-backed rule directory
- AWS EC2 Startup Shell Script Change · test · high · {"product":"aws","service":"cloudtrail"}
- Suspicious Commands Linux · test · medium · {"product":"linux","service":"auditd"}
- Potential Abuse of Linux Magic System Request Key · experimental · medium · {"product":"linux","service":"auditd","definition":"Required auditd configuration:\n-w /proc/sysrq-trigger -p wa -k sysrq\n-w /proc/sys/kernel/sysrq -p wa -k sysrq\n"}
- Equation Group Indicators · test · high · {"product":"linux"}
- Suspicious Activity in Shell Commands · test · high · {"product":"linux"}
- Suspicious Reverse Shell Command Line · test · high · {"product":"linux"}
- JexBoss Command Sequence · test · high · {"product":"linux"}
- Suspicious Filename with Embedded Base64 Commands · experimental · high · {"product":"linux","category":"file_event"}
- Linux Reverse Shell Indicator · test · critical · {"product":"linux","category":"network_connection"}
- BPFtrace Unsafe Option Usage · test · medium · {"category":"process_creation","product":"linux"}
- Suspicious Download and Execute Pattern via Curl/Wget · experimental · high · {"category":"process_creation","product":"linux"}
- Shell Invocation via Env Command - Linux · test · high · {"category":"process_creation","product":"linux"}
- Nohup Execution · test · medium · {"product":"linux","category":"process_creation"}
- Interactive Bash Suspicious Children · test · medium · {"product":"linux","category":"process_creation"}
- Script Interpreter Spawning Credential Scanner - Linux · experimental · high · {"category":"process_creation","product":"linux"}
Atlas deterministic concepts
T1059.004 Unix Shell
MATCH(shell_execution) AND command_line MATCHES suspicious_command_patterns -> ALERTAnomaly models
No exact Atlas model in this snapshot.
ATT&CK analytic guidance
DET0384 Behavioral Detection of Unix Shell Execution
AN1081 Analytic 1081
Detects bash, sh, zsh, or BusyBox shell execution initiated via remote sessions, unauthorized users, or embedded within secondary script interpreters. Focus is on chained behavior: shell > suspicious commands > network discovery or persistence indicators.
AN1082 Analytic 1082
Identifies use of sh/bash/zsh in suspicious context, such as user scripts launched from non-standard apps (e.g., Preview.app), embedded in LaunchDaemons, or executed outside Terminal.app. Looks for misuse in Automator, LaunchAgents, or NSAppleScript-executed shell.
AN1083 Analytic 1083
Detects BusyBox or Ash shell execution from unauthorized logins or remote connections. Focus is on rare shell invocations from DCUI, SSH sessions, or remote management paths. Also watches for payload droppers or persistence artifacts using shell.
AN1084 Analytic 1084
Detects Unix shell usage on network appliances (e.g., routers, firewalls, embedded Linux) through rare console commands, CLI interfaces, or script injection via exposed APIs or SSH.
Connected ecosystem references
Linked tags
Simulation, tools and telemetry
T1059.004 simulation workspace
- Command Execution · DC0064
- Logon Session Creation · DC0067
- Network Connection Creation · DC0082
- Network Traffic Flow · DC0078
- Process Creation · DC0032
- Script Execution · DC0029
No reviewed association in this snapshot.
Threat actor context
These are explicit actor-to-technique associations in the existing Threat Matrix snapshot, not attribution of an event or proof that a detector identifies the actor. No tool-to-actor relationship is inferred.
Existing anomaly research
Pinned research references. No browser attack runner, live simulation result or validated detector is asserted. Source mappings and validation limits are preserved. ATT&CK / Atomic provenance · Detection provenance.