Skip to content

Latest commit

 

History

History
35 lines (28 loc) · 1.21 KB

MATCH-S00164.md

File metadata and controls

35 lines (28 loc) · 1.21 KB

Rules: Suspicious Shells Spawned by Web Servers

Description

Web servers that spawn shell processes could be the result of a successfully placed web shell or an other attack

Additional Details

Detail Value
Type Templated Match
Category Persistence
Apply Risk to Entities device_hostname, device_ip, user_username
Signal Name Suspicious Shells Spawned by Web Servers
Summary Expression Parent process: {{parentBaseImage}} spawned process: {{baseImage}} on host: {{device_hostname}}
Score/Severity Static: 4
Enabled by Default True
Prototype False
Tags _mitreAttackTactic:TA0003, _mitreAttackTechnique:T1505, _mitreAttackTechnique:T1505.003

Vendors and Products

Fields Used

Origin Field
Normalized Schema baseImage
Normalized Schema device_hostname
Normalized Schema device_ip
Normalized Schema parentBaseImage
Normalized Schema user_username