MITRE ATT&CK technique
Server Software Component detection rulesT1505
Server Software Component (T1505) is a MITRE ATT&CK technique in the Persistence tactic. This page lists the 47 community-maintained Sigma detection rules in the library mapped to T1505 and its sub-techniques. Each rule includes its detection logic, log source, false positives and original YAML. These rules mainly target windows, linux, cisco.
Tactic
Certificate Request Export to Exchange Webserver
criticalDetects a write of an Exchange CSR to an untypical directory or with aspx name suffix which can be used to place a webshell
windows
CVE-2021-40539 Zoho ManageEngine ADSelfService Plus Exploit
criticalDetects an authentication bypass vulnerability affecting the REST API URLs in ADSelfService Plus (CVE-2021-40539).
webserver
Mailbox Export to Exchange Webserver
criticalDetects a successful export of an Exchange mailbox to untypical directory or with aspx name suffix which can be used to place a webshell or the needed role assignment for it
windows
Oracle WebLogic Exploit
criticalDetects access to a webshell dropped into a keystore folder on the WebLogic server
webserver
Solarwinds SUPERNOVA Webshell Access
criticalDetects access to SUPERNOVA webshell as described in Guidepoint report
webserver
Webshell Remote Command Execution
criticalDetects possible command execution by web application/web shell
linux
WordPress Wp2shell Webshell Plugin Access
criticalDetects post-exploitation access to the wp2shell webshell plugin dropped after successful exploitation of CVE-2026-63030 and CVE-2026-60137. After the pre-auth SQLi-to-admin bridge is established, the attacker can upload a malicious plugin (wp2shell) to the target WordPress instance. At this phase, the attacker accesses the webshell for command execution and persistence.
webserver
Antivirus - Web Shell Detection Signature
highDetects a highly relevant Antivirus alert that reports a web shell. It's highly recommended to tune this rule to the specific strings used by your anti virus solution by downloading a big WebShell repository from e.g. github and checking the matches. This event must not be ignored just because the AV has blocked the malware but investigate, how it came there in the first place.
antivirus
Chopper Webshell Process Pattern
highDetects patterns found in process executions cause by China Chopper like tiny (ASPX) webshells
windows · process_creation
Commvault QOperation Path Traversal Webshell Drop (CVE-2025-57790)
highDetects the use of qoperation.exe with the -file argument to write a JSP file to the webroot, indicating a webshell drop. This is a post-authentication step corresponding to CVE-2025-57790.
windows · process_creation
DEWMODE Webshell Access
highDetects access to DEWMODE webshell as described in FIREEYE report
webserver
Exchange Set OabVirtualDirectory ExternalUrl Property
highRule to detect an adversary setting OabVirtualDirectory External URL property to a script in Exchange Management log
windows
Failed MSExchange Transport Agent Installation
highDetects a failed installation of a Exchange Transport Agent
windows
HTTP Logging Disabled On IIS Server
highDetects changes to of the IIS server configuration in order to disable HTTP logging for successful requests.
windows
Linux Webshell Indicators
highDetects suspicious sub processes of web server processes
linux · process_creation
MOVEit CVE-2023-34362 Exploitation Attempt - Potential Web Shell Request
highDetects get requests to specific files used during the exploitation of MOVEit CVE-2023-34362
webserver
Potential CVE-2023-27363 Exploitation - HTA File Creation By FoxitPDFReader
highDetects suspicious ".hta" file creation in the startup folder by Foxit Reader. This can be an indication of CVE-2023-27363 exploitation.
windows · file_event
Potential Java WebShell Upload in SAP NetViewer Server
highDetects potential Java webshell uploads via HTTP requests with Content-Type 'application/octet-stream' and Java file extensions. This behavior might indicate exploitation of vulnerabilities like CVE-2025-31324, which allows remote code execution through webshells in SAP NetViewer.
webserver
Potential SAP NetViewer Webshell Command Execution
highDetects potential command execution via webshell in SAP NetViewer through JSP files with cmd parameter. This rule is created to detect exploitation of vulnerabilities like CVE-2025-31324, which allows remote code execution via a webshell.
webserver
Rejetto HTTP File Server RCE
highDetects attempts to exploit a Rejetto HTTP File Server (HFS) via CVE-2014-6287
webserver
Shellshock Expression
highDetects shellshock expressions in log files
linux
Suspicious ASPX File Drop by Exchange
highDetects suspicious file type dropped by an Exchange component in IIS into a suspicious folder
windows · file_event
Suspicious Child Process Of SQL Server
highDetects suspicious child processes of the SQLServer process. This could indicate potential RCE or SQL Injection.
windows · process_creation
Suspicious File Write to SharePoint Layouts Directory
highDetects suspicious file writes to SharePoint layouts directory which could indicate webshell activity or post-exploitation. This behavior has been observed in the exploitation of SharePoint vulnerabilities such as CVE-2025-49704, CVE-2025-49706 or CVE-2025-53770.
windows · file_event
Suspicious IIS Module Registration
highDetects a suspicious IIS module registration as described in Microsoft threat report on IIS backdoors
windows · process_creation
Suspicious MSExchangeMailboxReplication ASPX Write
highDetects suspicious activity in which the MSExchangeMailboxReplication process writes .asp and .apsx files to disk, which could be a sign of ProxyShell exploitation
windows · file_event
Suspicious Process By Web Server Process
highDetects potentially suspicious processes being spawned by a web server process which could be the result of a successfully placed web shell or exploitation
windows · process_creation
Suspicious Process Spawned by CentreStack Portal AppPool
highDetects unexpected command shell execution (cmd.exe) from w3wp.exe when tied to CentreStack's portal.config, indicating potential exploitation (e.g., CVE-2025-30406)
windows · process_creation
Suspicious Windows Strings In URI
highDetects suspicious Windows strings in URI which could indicate possible exfiltration or webshell communication
webserver
Webshell Detection With Command Line Keywords
highDetects certain command line parameters often used during reconnaissance activity via web shells
windows · process_creation
Webshell Hacking Activity Patterns
highDetects certain parent child patterns found in cases in which a web shell is used to perform certain credential dumping or exfiltration activities on a compromised system
windows · process_creation
Webshell ReGeorg Detection Via Web Logs
highCertain strings in the uri_query field when combined with null referer and null user agent can indicate activity associated with the webshell ReGeorg.
webserver
Webshell Tool Reconnaissance Activity
highDetects processes spawned from web servers (PHP, Tomcat, IIS, etc.) that perform reconnaissance looking for the existence of popular scripting tools (perl, python, wget) on the system via the help commands
windows · process_creation
Windows Webshell Strings
highDetects common commands used in Windows webshells
webserver
Cisco Modify Configuration
mediumModifications to a config that will serve an adversary's impacts or persistence
cisco
ETW Logging/Processing Option Disabled On IIS Server
mediumDetects changes to of the IIS server configuration in order to disable/remove the ETW logging/processing option.
windows
Execution From Webserver Root Folder
mediumDetects a program executing from a web server root folder. Use this rule to hunt for potential interesting activity such as webshell or backdoors
windows · process_creation
IIS Native-Code Module Command Line Installation
mediumDetects suspicious IIS native-code module installations via command line
windows · process_creation
MSExchange Transport Agent Installation
mediumDetects the Installation of a Exchange Transport Agent
windows · process_creation
MSExchange Transport Agent Installation - Builtin
mediumDetects the Installation of a Exchange Transport Agent
windows
New Module Module Added To IIS Server
mediumDetects the addition of a new module to an IIS server.
windows
Potential Suspicious Activity Using SeCEdit
mediumDetects potential suspicious behaviour using secedit.exe. Such as exporting or modifying the security policy
windows · process_creation
Potential Webshell Creation On Static Website
mediumDetects the creation of files with certain extensions on a static web site. This can be indicative of potential uploads of a web shell.
windows · file_event
Suspicious File Drop by Exchange
mediumDetects suspicious file type dropped by an Exchange component in IIS
windows · file_event
Suspicious File Write to Webapps Root Directory
mediumDetects suspicious file writes to the root directory of web applications, particularly Apache web servers or Tomcat servers. This may indicate an attempt to deploy malicious files such as web shells or other unauthorized scripts.
windows · file_event
Suspicious SQL Query
mediumDetects suspicious SQL query keywrods that are often used during recon, exfiltration or destructive activities. Such as dropping tables and selecting wildcard fields
database
Previously Installed IIS Module Was Removed
lowDetects the removal of a previously installed IIS module.
windows