A reverse shell connection is a way for an attacker to call back to a malicious server from a compromised system. This is often done once the attacker has already gained access to a system and needs to establish an impromptu interactive shell. The attacker's options for initiating a reverse shell are limited by the scripting languages installed on the target system. Hence, our detections are focused on the scripting languages that are commonly installed on macOS or installed by default.