Javascript Reverse Shell via Node.js
Description
This rule detects the creation of a Javascript reverse shell through Node.js. Attackers may spawn reverse shells to establish persistence onto a target system. By using Node.js, attackers may attempt to evade detection and leverage the platform's capabilities for various malicious purposes, such as downloading and executing payloads, establishing persistence, or exfiltrating data.
Query · eql
sequence by process.entity_id with maxspan=10s
[process where event.type == "start" and event.action == "exec" and process.name == "node" and
process.args == "node" and process.args_count == 2 and process.args : (
"/tmp/*.js", "/var/tmp/*.js", "/dev/shm/*.js", "/tmp/*.mjs", "/var/tmp/*.mjs", "/dev/shm/*.mjs"
)]
[network where event.type == "start" and event.action == "connection_attempted" and not (
destination.port == 53 or
cidrmatch(
destination.ip, "240.0.0.0/4", "233.252.0.0/24", "224.0.0.0/4", "198.19.0.0/16", "192.18.0.0/15",
"192.0.0.0/24", "10.0.0.0/8", "127.0.0.0/8", "169.254.0.0/16", "172.16.0.0/12", "192.0.2.0/24",
"192.31.196.0/24", "192.52.193.0/24", "192.168.0.0/16", "192.88.99.0/24", "100.64.0.0/10",
"192.175.48.0/24", "198.18.0.0/15", "198.51.100.0/24", "203.0.113.0/24", "::1", "FE80::/10",
"FF00::/8"
)
)
]