Rebound Shell

Last Updated At: 2025-10-15 16:09:52

This document describes how to view and process the details of the rebound shell, and guide you how to create an allowlist to set the allowed reverse connection behavior.

Background Information

Reverse shell functionality is based on multidimensional and multiple methods to identify and record the Shell reverse connection behavior on the server, providing your Cloud Virtual Machine with real-time monitoring capabilities for the reverse shell behavior.

Operation Steps

Alarm List

  1. Log in to the tenant console of Cloud Workload Protection Platform. In the left sidebar, select Intrusion Detection > Rebound Shell to enter the Rebound Shell Alarm List Page.
  2. On the Rebound Shell Alarm List tab page, you can view the rebound shell event list and perform related operations.
    You can view the name of the host/instance ID, IP address, connection process, etc. where the reverse Shell occurred. The list display fields are customizable.
    • Filter: The Rebound Shell Alarm List supports selecting a date to view corresponding events, querying events by keyword and tag (multiple keywords are separated by the vertical bar "|", and multiple filter tags are separated by the Enter key), and filtering alarms by status (all, pending, and confirmed).
    • Customize list fields: Above the Rebound Shell Alarm List to set the list display field. After completing the selection, click OK to successfully set.
    • Event export: Above the Rebound Shell Alarm List to export the Rebound Shell Alarm List.
    • Detailed information: In the right operation column of the target reverse Shell event, click Details to view the detailed information of the reverse Shell event.
      • Mark as processed: It is recommended that you manually handle the alarm by referring to the "Repair advice" in the alarm details. After handling, you can mark the alarm as processed.
      • Add to allowlist: After the add to allowlist operation, when the same situation occurs again, no Alarm will be triggered. Proceed with caution.
      • Ignore: Only ignore this Alarm. If the same situation occurs again, an alarm will still be triggered.
      • Delete a record: Delete this alarm record. The console will no longer display it. Deleted records cannot be restored. Proceed with caution.

Allowlist Management

Rebound Shell supports adding allowlists. By setting allowlist conditions, events that meet the conditions are marked as allowlisted.

  1. Log in to the tenant console of CWPP. In the left sidebar, select Intrusion Detection > Rebound Shell to enter the Rebound Shell page.
  2. On the Rebound Shell page, select Allowlist Management > Add Allowlist.
  3. In the Add Allowlist pop-up window, set the rebound Shell conditions, including: destination host, custom connection process (support multiple process names, separated by commas). At the same time, select the server range covered by the condition and click confirm.
    Field Description:
    • IP address format: single IP (127.0.0.1), IP range (127.0.0.1-127.0.0.254), IP network segment (127.0.0.1/24).
    • Port format: 80,8080 (separated by commas for multiple ports. Leave blank for no port limit).
    • Tick two conditions. They need to be satisfied simultaneously to hit allowlist.
    • If the server scope is set to all servers, add trust to all servers under the user's APPID for this allowlist condition. Proceed with caution.
  4. After the settings are completed, you can view the condition in the allowlist management list. Events that meet the condition in the alarm list will be marked as allowlist events.
  5. On the allowlist management page, you can perform filter and delete operations on the allowlist.
    • Filtering: The configured allowlist supports querying by keyword and tag (multiple keywords are separated by the vertical bar "|", and multiple filter tags are separated by the Enter key).
    • Customize list fields: Above the allowlist to set the list display field. After completing the selection, click OK to successfully set.
    • Edit: In the right operation column of the target allowlist, click Edit to edit the created allowlist.
    • Deletion: In the allowlist, deletion of the configured allowlist is supported.