This detection identifies adversaries deploying a JSP-based web shell named cmd_win32.jsp to establish persistent remote command execution capabilities on compromised web servers. Proactively hunting for this artifact in Azure Sentinel is critical because such shells often serve as an initial foothold that enables attackers to execute arbitrary commands, exfiltrate sensitive data, and pivot deeper into the internal network before triggering broader alerting mechanisms.
rule webshell_cmd_win32 {
meta:
description = "Web Shell - file cmd_win32.jsp"
license = "Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE"
author = "Florian Roth (Nextron Systems)"
date = "2014/01/28"
score = 70
hash = "cc4d4d6cc9a25984aa9a7583c7def174"
id = "393e738a-b4c2-5630-a55f-c3caee4ff75e"
strings:
$s0 = "Process p = Runtime.getRuntime().exec(\"cmd.exe /c \" + request.getParam"
$s1 = "<FORM METHOD=\"POST\" NAME=\"myform\" ACTION=\"\">" fullword
condition:
2 of them
}
This YARA rule can be deployed in the following contexts:
This rule contains 2 string patterns in its detection logic.
Here are 5 specific false positive scenarios for the Web Shell - file cmd_win32.jsp detection rule, including suggested filters and exclusions:
Scenario: Automated Deployment via CI/CD Pipeline
cmd_win32.jsp file (part of the base application artifact) into the Tomcat/IIS web root directory every morning at 08:00 AM via an automated build agent.InitiatingProcessName is jenkins-agent.exe, gitlab-runner.exe, or msbuild.exe, and the AccountName matches the service account used by the CI tool (e.g., svc-deploy).Scenario: Scheduled Backup of Web Artifacts
cmd_win32.jsp within the application directory without actually modifying the content permanently in a way that suggests a new shell upload.InitiatingProcessName is VeeamAgent.exe (or specific backup software processes) occurring between 02:00 and 04:00 daily. Alternatively, exclude if the file hash matches the known “Golden Image” hash of the legitimate application artifact.Scenario: Admin Manual Maintenance via Remote Desktop