IT Forensics · Linux

Forensic reconstruction of reverse shells – Forensic detection of outbound remote access by attackers

A reverse shell is a connection actively established from a compromised system to a Server controlled by the attacker, via which the attacker is provided with an interactive command line on the affected system.

Enquire without obligation

As such a connection originates from the compromised system itself, it can sometimes more easily bypass perimeter-based security measures, which primarily monitor incoming connections.

Why LanCologne?

Since its foundation, LanCologne has specialised in professional IT forensics. Our staff have decades of experience in the field of information technology and assist companies, solicitors, private individuals and, on a regular basis, the courts in the technical investigation of complex digital matters.

The examination is, as a matter of principle, carried out exclusively on a forensic copy, a forensic image or a data source captured in a technically equivalent manner that preserves the integrity of the evidence. The original evidence remains unchanged and is stored in a manner that preserves its integrity.

Our services

We examine systems for evidence of the use of reverse shells, reconstruct the associated network connections and process activities, and, as far as possible, assign a timeline to the commands executed.

Typical areas of application

Evidence of the use of a reverse shell
Reconstruction of commands executed via a reverse shell
Identification of the attacker’s target infrastructure
Assessment of the scope of access gained via the connection
Incident Response on Linux Systems
Judicial and non-judicial expert reports

This is how a reverse shell investigation is carried out

Once the system has been secured, available network and process artefacts are examined for evidence of outgoing, atypical connections. The associated triggering processes and tools used are identified and combined with other system artefacts to form a chronological timeline.

Why is the investigation into reverse shells relevant from a forensic perspective?

A reverse shell often provides an attacker with a direct, interactive means of access, which is why its forensic reconstruction can yield key insights into the extent and duration of such access.

Knowledge of the target infrastructure used by the attacker may also be important for further action and for potentially attributing the incident.

Frequently Asked Questions

How does a reverse shell differ from a traditional shell connection?+
In a reverse shell, the compromised system actively establishes a connection with the attacker, rather than the attacker actively connecting to the system.
Can a reverse shell connection that has already been terminated still be detected?+
Provided that the relevant network, process or log artefacts are still available, this is possible in many cases.
Which tools are commonly misused for reverse shells?+
These include, amongst other things, common interpreters and network tools – which are already present on many systems – that are being used for purposes other than those for which they were intended.

LanCologne – Linux Forensics Cologne

Do you require a professional forensic investigation into „the forensic reconstruction of reverse shells"? LanCologne can assist you in the court-admissible preservation of digital evidence and the transparent analysis of relevant Linux artefacts.

Get in touch now