← Back to Explore
T1546.005
Trap
Adversaries may establish persistence by executing malicious content triggered by an interrupt signal. The <code>trap</code> command allows programs and shells to specify commands that will be executed upon receiving interrupt signals. A common situation is a script allowing for graceful termination and handling of common keyboard interrupts like <code>ctrl+c</code> and <code>ctrl+d</code>. Adversaries can use this to register code to be executed when the shell encounters specific interrupts as...
macOSLinux
1
Detections
1
Sources
0
Threat Actors
BY SOURCE
1elastic
PROCEDURES (1)
General Monitoring1 detections
Auto-extracted: 1 detections for general monitoring