This detection identifies adversaries deploying a cmd.jsp web shell to establish persistence and execute remote commands on compromised web servers within the Azure environment. Proactive hunting for this specific artifact is critical because JSP-based shells often evade standard signature-based defenses, allowing attackers to maintain stealthy access and pivot through the network before triggering broader alerts.
rule webshell_jsp_cmd {
meta:
description = "Web Shell - file cmd.jsp"
license = "Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE"
author = "Florian Roth (Nextron Systems)"
date = "2014/01/28"
score = 70
hash = "5391c4a8af1ede757ba9d28865e75853"
id = "393e738a-b4c2-5630-a55f-c3caee4ff75e"
strings:
$s6 = "out.println(\"Command: \" + request.getParameter(\"cmd\") + \"<BR>\");" fullword
condition:
all of them
}
This YARA rule can be deployed in the following contexts:
This rule contains 1 string patterns in its detection logic.
Here are 4 specific false positive scenarios for the Web Shell - file cmd.jsp detection rule, including tailored filters and exclusions suitable for an enterprise environment:
Scenario: Deployment of Standard JSP Templates via CI/CD Pipeline
.jsp) files. The deployment script often creates a generic cmd.jsp file in the web root directory as part of the initial setup for new microservices or legacy modules.10.50.20.0/24) and the file hash matches a known baseline signature stored in the artifact repository (e.g., Artifactory or Nexus).Scenario: Scheduled Maintenance and Health Check Scripts
cmd.jsp files to execute diagnostic commands, check server health, or clear logs on the Tomcat or WebLogic servers. This activity often occurs between 02:00 and 04:00 UTC.02:00–04:00 daily) specifically on hosts tagged as “Production-AppServer,” provided the file creation user is the service account svc-tomcat-admin.Scenario: Legitimate Administrative Debugging by Application Support
cmd.jsp in the `/webapps