Suspicious Child Process of SAP NetWeaver - Linux
Detects suspicious child processes spawned by SAP NetWeaver on Linux systems that could indicate potential exploitation of vulnerability that allows arbitrary execution via webshells such as CVE-2025-31324.
Detection logic
selection_parent_img
ParentImage|contains:
- /j2ee/cluster/apps/sap.com/irj/servlet_jsp/irj/work
- /j2ee/cluster/apps/sap.com/irj/servlet_jsp/irj/rootselection_current_dict
CurrentDirectory|contains:
- /j2ee/cluster/apps/sap.com/irj/servlet_jsp/irj/work
- /j2ee/cluster/apps/sap.com/irj/servlet_jsp/irj/rootselection_child
Image|endswith:
- /ash
- /bash
- /csh
- /dash
- /ksh
- /sh
- /tcsh
- /zsh
- /python
- /python2
- /python3
- /perl
- /ruby
- /curl
- /wget
- /nc
- /netcat
- /ncat
- /socat
- /nmap
- /telnet
- /awk
- /sedCondition
(selection_parent_img or selection_current_dict) and selection_childRaw YAML
title: Suspicious Child Process of SAP NetWeaver - Linux
id: 69dea60b-2deb-4c9e-a685-ad542f4367f9
status: experimental
description: |
Detects suspicious child processes spawned by SAP NetWeaver on Linux systems that could indicate potential
exploitation of vulnerability that allows arbitrary execution via webshells such as CVE-2025-31324.
author: Elastic (idea), Swachchhanda Shrawan Poudel (Nextron Systems)
date: 2025-04-28
tags:
- attack.execution
- attack.initial-access
- attack.t1190
- attack.persistence
- attack.t1059.003
- cve.2025-31324
- detection.emerging-threats
references:
- https://reliaquest.com/blog/threat-spotlight-reliaquest-uncovers-vulnerability-behind-sap-netweaver-compromise/
- https://onapsis.com/blog/active-exploitation-of-sap-vulnerability-cve-2025-31324/
logsource:
category: process_creation
product: linux
detection:
selection_parent_img:
ParentImage|contains:
- '/j2ee/cluster/apps/sap.com/irj/servlet_jsp/irj/work'
- '/j2ee/cluster/apps/sap.com/irj/servlet_jsp/irj/root'
selection_current_dict:
CurrentDirectory|contains:
- '/j2ee/cluster/apps/sap.com/irj/servlet_jsp/irj/work'
- '/j2ee/cluster/apps/sap.com/irj/servlet_jsp/irj/root'
selection_child:
Image|endswith:
- '/ash'
- '/bash'
- '/csh'
- '/dash'
- '/ksh'
- '/sh'
- '/tcsh'
- '/zsh'
- '/python'
- '/python2'
- '/python3'
- '/perl'
- '/ruby'
- '/curl'
- '/wget'
- '/nc'
- '/netcat'
- '/ncat'
- '/socat'
- '/nmap'
- '/telnet'
- '/awk'
- '/sed'
condition: (selection_parent_img or selection_current_dict) and selection_child
falsepositives:
- Legitimate administrative activities such as software updates
level: mediumFalse positives
- Legitimate administrative activities such as software updates
References
Similar rules
Suspicious Child Process of SAP NetWeaver
mediumwindows · Shares T1190, T1059
Potential SAP NetWeaver Webshell Creation - Linux
mediumlinux · Shares T1190, T1059
Atlassian Confluence CVE-2022-26134
highlinux · Shares T1190, T1059
CVE-2023-22518 Exploitation Attempt - Suspicious Confluence Child Process (Linux)
highlinux · Shares T1059, T1190