1200KM / simulation
T1546.005 Trap — Attack Simulation
Adversaries may establish persistence by executing malicious content triggered by an interrupt signal. The trap command allows programs and shells to specify commands that will be executed upon receiving interrupt signals. A common situation is a script allowing for graceful termination and handling of common keyboard interrupts like ctrl+c and ctrl+d. Adversaries can use this to register code to be executed when the shell encounters specific…
Technique description
Adversaries may establish persistence by executing malicious content triggered by an interrupt signal. The trap command allows programs and shells to specify commands that will be executed upon receiving interrupt signals. A common situation is a script allowing for graceful termination and handling of common keyboard interrupts like ctrl+c and ctrl+d. Adversaries can use this to register code to be executed when the shell encounters specific…
At least one platform-compatible Atomic procedure is documented. Individual review, lab prerequisites, and validation remain required.
Official ATT&CK definition · Detection rules and anomaly models
Documented simulation candidates
- Trap DEBUG - Log All Shell Commands
Procedure 14bd90b1-c3f3-4115-9861-cf0519a59654; elevation not declared required; cleanup present, not reviewed. Not executed or individually validated.
- Trap SIGINT
Procedure a547d1ba-1d7a-4cc5-a9cb-8d65e8809636; elevation not declared required; cleanup present, not reviewed. Not executed or individually validated.
- Trap EXIT
Procedure a74b2e07-5952-4c03-8b56-56274b076b61; elevation not declared required; cleanup present, not reviewed. Not executed or individually validated.
- Trap SIGINT (freebsd)
Procedure ade10242-1eac-43df-8412-be0d4c704ada; elevation not declared required; cleanup present, not reviewed. Not executed or individually validated.
- Trap EXIT (freebsd)
Procedure be1a5d70-6865-44aa-ab50-42244c9fd16f; elevation not declared required; cleanup present, not reviewed. Not executed or individually validated.
Connected ecosystem references
Linked tags
Detection and collection
Attack tools
No reviewed association in this snapshot.
Existing research
Pinned research references. No browser attack runner, live simulation result or validated detector is asserted. Source mappings and validation limits are preserved. ATT&CK / Atomic provenance · Detection provenance.