logo

Hunting reverse shells: How the Sysdig Threat Research Team builds smarter detection rules

ID: 737f6035-03fb-5c54-96a0-f126d19d70ac

STIX ID: report--737f6035-03fb-5c54-96a0-f126d19d70ac

Feed Name: Sysdig Blog

Date Published: 2025-11-13

Date Updated: 2026-05-01

...
...

Sysdig’s Threat Research Team details the anatomy of TCP reverse shells, categorizing direct shell execution, indirect execution via IPC, and direct command execution variants, and mapping them to Linux syscalls, file descriptor handling, and IPC primitives. The article explains limitations of earlier detections and introduces improved Falco process STDIN/STDOUT/STDERR context fields and stateful observation rules to reliably identify multi-step reverse shell patterns while reducing false positives.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.