"bash_reverse_shell": {
"query": "SELECT * FROM processes WHERE cmdline LIKE '/bin/bash -i >& /dev/tcp/%';",
"interval": 30,
"description": "Looks for processes that resemble a bash reverse shell"
}
index=osquery name=bash_reverse_shell
"bash_reverse_shell": {
"query": "SELECT * FROM process_events;",
"interval": 10,
"description": "Collect data about all running processes via process auditing"
}
index=osquery name=process_events columns.cmdline="/bin/bash -i >& /dev/tcp/*"