The script forces the host to initiate an outbound TCP connection, handing the attacker an interactive reverse shell so they can issue commands and receive results in real time.
According to the MITRE ATT&CK framework, which tactic best categorizes this behavior?
This behavior falls under the Command and Control tactic because the attacker establishes a channel (the reverse shell) that lets them send commands to, and receive output from, the compromised system. Initial Access pertains to the first foothold; Privilege Escalation is about gaining higher permissions; Impact covers destructive or disruptive actions. None of those directly describe maintaining an interactive remote session.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is a reverse shell?
Open an interactive chat with Bash
What is the role of PowerShell in cyberattacks?
Open an interactive chat with Bash
How does the MITRE ATT&CK framework classify Command and Control tactics?