EXPLORE
← Back to Explore
T1546.005

Trap

Adversaries may establish persistence by executing malicious content triggered by an interrupt signal. The <code>trap</code> command allows programs and shells to specify commands that will be executed upon receiving interrupt signals. A common situation is a script allowing for graceful termination and handling of common keyboard interrupts like <code>ctrl+c</code> and <code>ctrl+d</code>. Adversaries can use this to register code to be executed when the shell encounters specific interrupts as...

macOSLinux
1
Detections
1
Sources
0
Threat Actors

BY SOURCE

1elastic

PROCEDURES (1)

General Monitoring1 detections

Auto-extracted: 1 detections for general monitoring

DETECTIONS (1)