T1546.005 — Trap
T1546.005: Trap
MITRE ATT&CK® Enterprise technique
| Tactics | Privilege Escalation, Persistence |
| Platforms | macOS, Linux |
| Permissions required | — |
| Version | 1.1 |
| Parent technique | T1546 |
Description
Adversaries may establish persistence by executing malicious content triggered by an interrupt signal. The <code>trap</code> command allows programs and shells to specify commands that will be executed upon receiving interrupt signals. A common situation is a script allowing for graceful termination and handling of common keyboard interrupts like <code>ctrl+c</code> and <code>ctrl+d</code>.
Adversaries can use this to register code to be executed when the shell encounters specific interrupts as a persistence mechanism. Trap commands are of the following format <code>trap 'command list' signals</code> where "command list" will be executed when "signals" are received.(Citation: Trap Manual)(Citation: Cyberciti Trap Statements)
Detection
(no detection guidance published)
Data sources
- (none listed)
References
- ATT&CK page: https://attack.mitre.org/techniques/T1546/005
- ATT&CK Enterprise matrix: https://attack.mitre.org/matrices/enterprise/