Webshell Remote Command Execution

 Original Source: [Sigma source]
Title: Webshell Remote Command Execution
Status: test
Description:Detects possible command execution by web application/web shell
References:
  -Personal Experience of the Author
  -https://www.vaadata.com/blog/what-is-command-injection-exploitations-and-security-best-practices/
Author: Ilyas Ochkov, Beyu Denis, oscd.community
Date: 2019-10-12
modified:2025-12-05
Tags:
  • -'attack.persistence'
  • -'attack.t1505.003'
Logsource:
  • product: linux
  • service: auditd
  • definition: Required auditd configuration: -a always,exit -F arch=b32 -S execve -F euid=33 -k detect_execve_www -a always,exit -F arch=b64 -S execve -F euid=33 -k detect_execve_www -a always,exit -F arch=b32 -S execveat -F euid=33 -k detect_execve_www -a always,exit -F arch=b64 -S execveat -F euid=33 -k detect_execve_www Change the number "33" to the ID of your WebServer user. Default: www-data:x:33:33
Detection:
  selection:
    type: 'SYSCALL'
    SYSCALL:
      -'execve'
      -'execveat'

    euid: '33'
  condition:selection
Falsepositives:
  -Admin activity
  -Crazy web applications
Level: critical