This website uses cookies to ensure you get the best experience.
Got it!
Register
|
Login
Menu
Home
Sigma Rules
Splunk Rules
Explore Rules
Analytic Stories
MITRE ATT&CK
Overview
Matrix
Techniques
Groups
Software
Campaigns
Search
About
Webshell Remote Command Execution
Original Source:
[Sigma source]
Title:
Webshell Remote Command Execution
Status:
test
Description:
Detects possible command execution by web application/web shell
References:
-Personal Experience of the Author
-https://www.vaadata.com/blog/what-is-command-injection-exploitations-and-security-best-practices/
Author:
Ilyas Ochkov, Beyu Denis, oscd.community
Date:
2019-10-12
modified:
2025-12-05
Tags:
-'attack.persistence'
-'attack.t1505.003'
Logsource:
product: linux
service: auditd
definition: Required auditd configuration: -a always,exit -F arch=b32 -S execve -F euid=33 -k detect_execve_www -a always,exit -F arch=b64 -S execve -F euid=33 -k detect_execve_www -a always,exit -F arch=b32 -S execveat -F euid=33 -k detect_execve_www -a always,exit -F arch=b64 -S execveat -F euid=33 -k detect_execve_www Change the number "33" to the ID of your WebServer user. Default: www-data:x:33:33
Detection:
selection:
type
:
'SYSCALL'
SYSCALL
:
-'execve'
-'execveat'
euid
:
'33'
condition
:
selection
Falsepositives:
-Admin activity
-Crazy web applications
Level:
critical