logo

Man in the Terminal

ID: de73d149-9f3a-5e91-8bf1-6b39375d2d3d

STIX ID: report--de73d149-9f3a-5e91-8bf1-6b39375d2d3d

Feed Name: SpecterOps Blog

Date Published: 2021-04-05

Date Updated: 2026-04-30

Author: Dwight Hohnstein

...
...

This write-up presents a command-line interception technique for Unix-like systems that leverages PATH hijacking and shell rc file changes to place proxy middleware binaries ahead of legitimate tools (e.g., ssh), enabling transparent capture of stdin/stdout/stderr for pseudo-keylogging and session logging. It further explores broadening coverage by changing a user’s login shell to the middleware, highlighting practical implications for red teams while maintaining normal user workflows.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.