logo

Hunting reverse shells: How the Sysdig Threat Research Team builds smarter detection rules

ID: 6fbea003-06de-5f27-af74-e3233b79d480

STIX ID: report--6fbea003-06de-5f27-af74-e3233b79d480

Feed Name: Sysdig Blog

Date Published: 2025-11-13

Date Updated: 2026-05-01

...
...

This Sysdig Threat Research Team article analyzes TCP-based reverse-shell techniques (direct shell execution with network-redirected I/O, indirect execution using a secondary process with IPC, and direct command execution with network-redirected I/O), details the relevant Linux syscalls and file-descriptor/IPC behaviors, and describes how Sysdig/Falco detection rules and stateful observation policies were evolved to improve detection and reduce false positives.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.