A common attack pattern is a ZSH syntax which is used to create a reverse shell. This is often done after the attacker has already gained access to a system and needs to establish an impromptu interactive shell. A reverse shell is a common technique used by attackers to command and control compromised systems by connecting back to the attacker's system. This allows the attacker to gain control over the compromised machine, typically for the purposes of performing reconnaissance, executing further attack stages, or performing data exfiltration.
Use this test to evaluate how advance threat control can block and report a reverse shell ZSH (ATCReverseShellZSH) attack.
In a your test plan in Jamf Protect, make sure the Advanced Threat Controls setting is set to Block and Report or Report Only.
If using a virtual machine, take a snapshot to revert back to at the end of this simulation.