PUA - Netcat Suspicious Execution

 Original Source: [Sigma source]
Title: PUA - Netcat Suspicious Execution
Status: test
Description:Detects execution of Netcat. Adversaries may use a non-application layer protocol for communication between host and C2 server or among infected hosts within a network
References:
  -https://nmap.org/ncat/
  -https://github.com/redcanaryco/atomic-red-team/blob/f339e7da7d05f6057fdfcdd3742bfcf365fee2a9/atomics/T1095/T1095.md
  -https://www.revshells.com/
Author: frack113, Florian Roth (Nextron Systems)
Date: 2021-07-21
modified:2023-02-08
Tags:
  • -'attack.command-and-control'
  • -'attack.t1095'
Logsource:
  • category: process_creation
  • product: windows
Detection:
  selection_img:
    Image|endswith:
      -'\nc.exe'
      -'\ncat.exe'
      -'\netcat.exe'

  selection_cmdline:
    CommandLine|contains:
      -' -lvp '
      -' -lvnp'
      -' -l -v -p '
      -' -lv -p '
      -' -l --proxy-type http '
      -' -vnl --exec '
      -' -vnl -e '
      -' --lua-exec '
      -' --sh-exec '

  condition:1 of selection_*
Falsepositives:
  -Legitimate ncat use
Level: high