IT Forensics · Linux
Forensic reconstruction of reverse shells – Forensic detection of outbound remote access by attackers
A reverse shell is a connection actively established from a compromised system to a Server controlled by the attacker, via which the attacker is provided with an interactive command line on the affected system.
As such a connection originates from the compromised system itself, it can sometimes more easily bypass perimeter-based security measures, which primarily monitor incoming connections.
Why LanCologne?
Since its foundation, LanCologne has specialised in professional IT forensics. Our staff have decades of experience in the field of information technology and assist companies, solicitors, private individuals and, on a regular basis, the courts in the technical investigation of complex digital matters.
The examination is, as a matter of principle, carried out exclusively on a forensic copy, a forensic image or a data source captured in a technically equivalent manner that preserves the integrity of the evidence. The original evidence remains unchanged and is stored in a manner that preserves its integrity.
Our services
We examine systems for evidence of the use of reverse shells, reconstruct the associated network connections and process activities, and, as far as possible, assign a timeline to the commands executed.
Typical areas of application
This is how a reverse shell investigation is carried out
Once the system has been secured, available network and process artefacts are examined for evidence of outgoing, atypical connections. The associated triggering processes and tools used are identified and combined with other system artefacts to form a chronological timeline.
Why is the investigation into reverse shells relevant from a forensic perspective?
A reverse shell often provides an attacker with a direct, interactive means of access, which is why its forensic reconstruction can yield key insights into the extent and duration of such access.
Knowledge of the target infrastructure used by the attacker may also be important for further action and for potentially attributing the incident.
Frequently Asked Questions
LanCologne – Linux Forensics Cologne
Do you require a professional forensic investigation into „the forensic reconstruction of reverse shells"? LanCologne can assist you in the court-admissible preservation of digital evidence and the transparent analysis of relevant Linux artefacts.
Related to this topic
- Forensic analysis of Linux ransomware – reconstructing encryption attacks on Linux systems
- Forensic evidence of SSH brute-force attacks – Providing forensic evidence of systematic login attempts
- Proving privilege escalation through forensic analysis – reconstructing unauthorised expansion of privileges
- Detecting log manipulation and anti-forensics – uncovering evidence tampering on Linux systems