Skip to content

Hide Navigation Hide TOC

Shell Invocation via Apt - Linux (bb382fd5-b454-47ea-a264-1828e4c766d6)

Detects the use of the "apt" and "apt-get" commands to execute a shell or proxy commands. Such behavior may be associated with privilege escalation, unauthorized command execution, or to break out from restricted environments.

Cluster A Galaxy A Cluster B Galaxy B Level
File and Directory Discovery - T1083 (7bc57495-ea59-4380-be31-a64af124ef18) Attack Pattern Shell Invocation via Apt - Linux (bb382fd5-b454-47ea-a264-1828e4c766d6) Sigma-Rules 1