Command and Scripting Interpreter: Unix Shell

Description

Adversaries may abuse Unix shell commands and scripts for execution. Unix shells are the primary command prompt on Linux and macOS systems, though many variations of the Unix shell exist (e.g. sh, bash, zsh, etc.) depending on the specific OS or distribution.[1][2] Unix shells can control every aspect of a system, with certain commands requiring elevated privileges.

Products, Sensors, and Dependencies

ProductDependenciesData sourceAccess requiredProtocolData CollectedNotes
Tenable Vulnerability ManagementAdvanced Network ScanLinux machinesSSH ScanSSHUser List EnumerationPlugin ID: 95928

References

Linux User List Enumeration

Attack Path Technique Details

Framework: MITRE ATT&CK

Family: Execution

Sub-Technique: Unix Shell

Platform: Linux

Tenable Release Date: 2024 Q1