High

Shell Configuration Modification

This rule flags attempts to modify files like .bashrc, .bash_profile, or .ssh/authorized_keys through an AI agent's command execution or file editing tools. These files are common places attackers plant persistence mechanisms so their access survives a reboot or session end.

How the attack works

An attacker with some level of access to a system uses shell append commands or a file-editing tool to write into shell startup files (such as .bashrc or .profile) or into the SSH authorized_keys file. Appending to a shell startup file lets them run arbitrary commands every time a new shell session starts. Adding an SSH key to authorized_keys gives them a durable login path that does not depend on stolen passwords. Either action is typically a persistence step taken after initial access has already been gained.

Netzilo detection

Netzilo can block this behaviour when it is observed.

Signature ID
1e785c77-6d77-5c79-ae24-6a389f9ef7f1
Severity
High

Why it matters

An organisation can lose control over when and how an attacker keeps returning to a compromised system, since these changes create a foothold that survives normal cleanup like closing a shell or ending a session.

What you can do

  • Review recent changes to .bashrc, .bash_profile, .profile, .zshrc, and similar shell startup files for unexpected entries.
  • Audit ~/.ssh/authorized_keys files across systems for keys you cannot account for.
  • Restrict which processes and users can write to shell configuration and SSH key files.
  • Expect noise from legitimate tools like nvm, pyenv, rbenv, and package manager installers, and tune monitoring to distinguish routine developer setup from unexplained changes.

Known benign look-alikes

  • Legitimate shell customisation by developers adding aliases or PATH entries
  • Package managers that update shell profiles during installation
  • Development environment setup tools like nvm, pyenv, or rbenv

References

Related threats