T1505 Server Software Component
Adversaries may abuse legitimate extensible development features of servers to establish persistent access to systems. Enterprise server applications may include features that allow developers to write and install software or scripts to extend the functionality of the main application. Adversaries may install malicious components to extend and abuse server applications.(Citation:…
Who uses it · with stories on Jábega
Sigma rules to hunt it
- CVE-2021-40539 Zoho ManageEngine ADSelfService Plus Exploitcriticaltest · webserver
- Certificate Request Export to Exchange Webservercriticaltest · windows
- Mailbox Export to Exchange Webservercriticaltest · windows
- Oracle WebLogic Exploitcriticaltest · webserver
- Solarwinds SUPERNOVA Webshell Accesscriticaltest · webserver
- Webshell Remote Command Executioncriticaltest · linux
- Antivirus - Web Shell Detection Signaturehightest · antivirus
- Chopper Webshell Process Patternhightest · windows
- DEWMODE Webshell Accesshightest · webserver
- Exchange Set OabVirtualDirectory ExternalUrl Propertyhightest · windows
- Failed MSExchange Transport Agent Installationhightest · windows
- HTTP Logging Disabled On IIS Serverhightest · windows
- Linux Webshell Indicatorshightest · linux
- MOVEit CVE-2023-34362 Exploitation Attempt - Potential Web Shell Requesthightest · webserver
- Potential CVE-2023-27363 Exploitation - HTA File Creation By FoxitPDFReaderhightest · windows
- Rejetto HTTP File Server RCEhightest · webserver
- Shellshock Expressionhightest · linux
- Suspicious ASPX File Drop by Exchangehightest · windows
- Suspicious Child Process Of SQL Serverhightest · windows
- Suspicious IIS Module Registrationhightest · windows
- Suspicious MSExchangeMailboxReplication ASPX Writehightest · windows
- Suspicious Process By Web Server Processhightest · windows
- Suspicious Windows Strings In URIhightest · webserver
- Webshell Detection With Command Line Keywordshightest · windows
- Webshell Hacking Activity Patternshightest · windows
Showing 25 of 44.
Rules from SigmaHQ · Detection Rule License 1.1. Technique from MITRE ATT&CK®.