Server Software Component

T1505

Technique with 6 sub-techniques.View on attack.mitre.org

About this technique

Adversaries may abuse legitimate extensible development features of servers to establish persistent access to systems. Enterprise server applications may include features that allow developers to write and install software or scripts to extend the functionality of the main application. Adversaries may install malicious components to extend and abuse server applications.

Detection rules75

Rules on DetectionCode tagged with T1505 or one of its sub-techniques.

Sigma34

RuleLevelLog sourceTechnique
Certificate Request Export to Exchange Webservercriticalwindows / NULLT1505.003
Mailbox Export to Exchange Webservercriticalwindows / NULLT1505.003
Webshell Remote Command Executioncriticallinux / NULLT1505.003
Antivirus - Web Shell Detection SignaturehighNULL / antivirusT1505.003
Chopper Webshell Process Patternhighwindows / process_creationT1505.003
Exchange Set OabVirtualDirectory ExternalUrl Propertyhighwindows / NULLT1505.003
Failed MSExchange Transport Agent Installationhighwindows / NULLT1505.002
HTTP Logging Disabled On IIS Serverhighwindows / NULLT1505.004
Linux Webshell Indicatorshighlinux / process_creationT1505.003
Shellshock Expressionhighlinux / NULLT1505.003
Suspicious ASPX File Drop by Exchangehighwindows / file_eventT1505.003
Suspicious Child Process Of SQL Serverhighwindows / process_creationT1505.003
Suspicious File Write to SharePoint Layouts Directoryhighwindows / file_eventT1505.003
Suspicious IIS Module Registrationhighwindows / process_creationT1505.004
Suspicious MSExchangeMailboxReplication ASPX Writehighwindows / file_eventT1505.003

Splunk41

RuleTypeRiskData sourceTechnique
Cisco Configuration Archive Logging AnalysisHuntingNULLCisco IOS LogsT1505.003
Cisco Secure Firewall - Privileged Command Execution via HTTPAnomalyNULLCisco Secure Firewall Threat Defense Intrusion EventT1505.003
Confluence Unauthenticated Remote Code Execution CVE-2022-26134TTPNULLPalo Alto Network ThreatT1505
Detect Exchange Web ShellTTPNULLSysmon EventID 11T1505.003
Detect Webshell Exploit BehaviorTTPNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2T1505.003
ESXi Malicious VIB Forced InstallTTPNULLVMWare ESXi SyslogT1505.006
Exploit Public Facing Application via Apache Commons TextAnomalyNULLNginx AccessT1505.003
Linux Suspicious Redis ActivityTTPNULLSysmon for Linux EventID 1T1505
MS Exchange Mailbox Replication service writing Active Server PagesTTPNULLSysmon EventID 1 AND Sysmon EventID 11T1505.003
Spring4Shell Payload URL RequestTTPNULLNginx AccessT1505.003
Supernova WebshellTTPNULLT1505.003
Tomcat Session Deserialization AttemptAnomalyNULLNginx AccessT1505.003
Tomcat Session File Upload AttemptAnomalyNULLNginx AccessT1505.003
W3WP Spawning ShellTTPNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2T1505.003
Web JSP Request via URLTTPNULLNginx AccessT1505.003

Sub-techniques6

IDNameExamples
T1505.001SQL Stored Procedures2
T1505.002Transport Agent1
T1505.003Web Shell66
T1505.004IIS Components5
T1505.005Terminal Services DLL0
T1505.006vSphere Installation Bundles2

Groups0

None recorded.

Software0

None recorded.

Campaigns0

None recorded.

Procedure examples0

No procedure examples are recorded for this technique.

References1

  1. volexity_0day_sophos_FW Open source
    Adair, S., Lancaster, T., Volexity Threat Research. (2022, June 15). DriftingCloud: Zero-Day Sophos Firewall Exploitation and an Insidious Breach. Retrieved July 1, 2022.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.