Event Triggered Execution: Trap T1546.005

Tactics: Privilege Escalation, Persistence

Adversaries may establish persistence by executing malicious content triggered by an interrupt signal. The trap command allows programs and shells to specify commands that will be executed upon receiving interrupt signals. A common situation is a script allowing for graceful termination and handling of common keyboard interrupts like ctrl+c and ctrl+d.

Events covered

1 catalog event is tagged with this technique by at least one rule.

ProviderEventTitle
ESFexecProcess Execution

Authoring guide

These 1 rule share fields, values, and exclusions.

Fields filtered most (4 distinct)

These fields appear most often in rule filters.

FieldRulesHowSample values
EventType1in 1exec, exec_event, executed
event.type1eq 1start
process.args1starts_with 1SIG
process_name1eq 1trap

Top indicator values (7 distinct)

These values appear most often in rule predicates.

FieldKindValueRules (here)Corpus reach
EventTypein
exec
1206
EventTypein
exec_event
1150
EventTypein
executed
198
EventTypein
process_started
183
event.typeeq
start
11087
process.argsstarts_with
SIG
1
process_nameeq
trap
1

Rules under this technique

These vendors publish rules tagged with this technique.

Platform: macOS

Domain: Endpoint

Elastic 1 rule