heroui logo

Cisco NVM - Browser Spawned Unix Shell with External Connection

Splunk Security Content

View Source
Summary
This anomaly rule detects cases where a Unix-based browser process (on Linux or macOS) spawns a Unix shell (e.g., bash, sh, zsh, etc.) and the shell establishes an outbound connection to an external destination. It correlates the shell process path with a parent browser process path (Chrome, Brave, Firefox, Safari, etc.) and filters out common internal destinations to reduce false positives. The pattern can indicate malicious browser-driven content (drive-by execution, compromised websites, or abusive browser extensions) or legitimate developer/workflow activity in enterprise environments. The rule is focused on Unix-like endpoints and leverages Cisco Network Visibility Module Flow data to detect this browser-to-shell execution chain. While powerful for catching anomalous behavior, legitimate automation or software workflows may occasionally trigger this pattern, so environment-specific tuning is recommended. It aligns with MITRE ATT&CK T1059 (Command and Scripting Interpreter).
Categories
  • Endpoint
  • Linux
  • macOS
Data Sources
  • Certificate
  • Network Traffic
  • Process
ATT&CK Techniques
  • T1059
Created: 2026-09-06