This website uses cookies to ensure you get the best experience.
Got it!
Register
|
Login
Menu
Home
Sigma Rules
Splunk Rules
Explore Rules
Analytic Stories
MITRE ATT&CK
Overview
Matrix
Techniques
Groups
Software
Campaigns
Search
About
Webshell Detection With Command Line Keywords
Original Source:
[Sigma source]
Title:
Webshell Detection With Command Line Keywords
Status:
test
Description:
Detects certain command line parameters often used during reconnaissance activity via web shells
References:
-https://www.fireeye.com/blog/threat-research/2013/08/breaking-down-the-china-chopper-web-shell-part-ii.html
-https://unit42.paloaltonetworks.com/bumblebee-webshell-xhunt-campaign/
-https://www.huntress.com/blog/threat-advisory-oh-no-cleo-cleo-software-actively-being-exploited-in-the-wild
Author:
Florian Roth (Nextron Systems), Jonhnathan Ribeiro, Anton Kutepov, oscd.community, Chad Hudson, Matt Anderson
Date:
2017-01-01
modified:
2026-07-14
Tags:
-'attack.persistence'
-'attack.discovery'
-'attack.t1505.003'
-'attack.t1018'
-'attack.t1033'
-'attack.t1087'
Logsource:
category: process_creation
product: windows
Detection:
selection_webserver_image:
ParentImage|endswith
:
-'\w3wp.exe'
-'\php-cgi.exe'
-'\nginx.exe'
-'\httpd.exe'
-'\caddy.exe'
-'\ws_tomcatservice.exe'
selection_webserver_characteristics_tomcat1:
ParentImage|endswith
:
-'\java.exe'
-'\javaw.exe'
ParentImage|contains
:
-'-tomcat-'
-'\tomcat'
selection_webserver_characteristics_tomcat2:
ParentImage|endswith
:
-'\java.exe'
-'\javaw.exe'
CommandLine|contains
:
-'catalina.jar'
-'CATALINA_HOME'
selection_susp_net_utility:
OriginalFileName
:
-'net.exe'
-'net1.exe'
CommandLine|contains
:
-' user '
-' use '
-' group '
selection_susp_ping_utility:
OriginalFileName
:
'ping.exe'
CommandLine|contains
:
' -n '
selection_susp_change_dir:
CommandLine|contains
:
-'&cd&echo'
-'cd /d '
selection_susp_wmic_utility:
OriginalFileName
:
'wmic.exe'
CommandLine|contains
:
' /node:'
selection_susp_powershell_cli:
Image|endswith
:
-'\cmd.exe'
-'\powershell.exe'
-'\pwsh.exe'
CommandLine|contains
:
-' -enc '
-' -EncodedCommand '
-' -w hidden '
-' -windowstyle hidden'
-'.WebClient).Download'
selection_susp_misc_discovery_binaries:
- Image|endswith
:
- '\dsquery.exe'
- '\find.exe'
- '\findstr.exe'
- '\ipconfig.exe'
- '\netstat.exe'
- '\nslookup.exe'
- '\pathping.exe'
- '\quser.exe'
- '\schtasks.exe'
- '\systeminfo.exe'
- '\tasklist.exe'
- '\tracert.exe'
- '\wevtutil.exe'
- '\whoami.exe'
- OriginalFileName
:
- 'dsquery.exe'
- 'find.exe'
- 'findstr.exe'
- 'ipconfig.exe'
- 'netstat.exe'
- 'nslookup.exe'
- 'pathping.exe'
- 'quser.exe'
- 'schtasks.exe'
- 'sysinfo.exe'
- 'tasklist.exe'
- 'tracert.exe'
- 'VSSADMIN.EXE'
- 'wevtutil.exe'
- 'whoami.exe'
selection_susp_misc_discovery_commands:
CommandLine|contains
:
-' Test-NetConnection '
-'dir \'
condition
:
1 of selection_webserver_* and 1 of selection_susp_*
Falsepositives:
-Unknown
Level:
high