Splunk published a new analytic to detect Linux reverse shells that abuse shell pseudo-devices such as /dev/tcp and /dev/udp to open outbound connections from bash, sh, dash, or zsh without requiring tools like netcat. The detection, Linux Shell Pseudo Device Reverse Shell, is designed for Splunk Enterprise Security and uses EDR or Sysmon for Linux process telemetry mapped into the CIM Endpoint Processes data model to identify shell redirection patterns commonly used after compromise for remote access and command execution.
The analytic is mapped to MITRE ATT&CK techniques T1048.003 and T1059, linking the behavior to exfiltration over unencrypted non-C2 protocols and command-shell abuse. MITRE documents broad adversary use of alternative outbound protocols—including HTTP, FTP, SMTP, DNS, WebDAV, TCP, and TFTP—for data theft and covert transfer, as well as the use of legitimate utilities such as curl, ftp, WinSCP, and Rclone. Splunk said the detection generates intermediate risk events by default and warned that legitimate administrative diagnostics or testing can also trigger it, making environment-specific filtering important.

See real exploitation activity before you spend the cycle.
2 events from the most recent confirmed update back to the earliest known activity.
Splunk published or updated the "Linux Shell Pseudo Device Reverse Shell" analytic in Splunk Enterprise Security. The detection identifies shell use of /dev/tcp or /dev/udp to establish outbound connections and maps to ATT&CK techniques T1048.003 and T1059.
MITRE ATT&CK published the Enterprise sub-technique page for T1048.003, Exfiltration Over Unencrypted Non-C2 Protocol, documenting examples of threat groups, malware, and utilities that exfiltrate data over alternative unencrypted protocols.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
2 references tracked. Mallory keeps watching after this page renders.
research.splunk.com
Open sourceattack.mitre.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.