This detection identifies adversaries deploying a cmdjsp.jsp web shell to establish a persistent foothold for remote command execution and lateral movement within web applications. Proactive hunting is essential in Azure Sentinel to rapidly identify these often-overlooked artifacts before attackers leverage them for data exfiltration or privilege escalation.
rule webshell_jsp_cmdjsp_2 {
meta:
description = "Web Shell - file cmdjsp.jsp"
license = "Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE"
author = "Florian Roth (Nextron Systems)"
date = "2014/01/28"
score = 70
hash = "1b5ae3649f03784e2a5073fa4d160c8b"
id = "393e738a-b4c2-5630-a55f-c3caee4ff75e"
strings:
$s0 = "Process p = Runtime.getRuntime().exec(\"cmd.exe /C \" + cmd);" fullword
$s4 = "<FORM METHOD=GET ACTION='cmdjsp.jsp'>" fullword
condition:
all of them
}
This YARA rule can be deployed in the following contexts:
This rule contains 2 string patterns in its detection logic.
Here are 4 specific false positive scenarios for the Web Shell - file cmdjsp.jsp detection rule, including suggested filters and exclusions:
Scheduled Backup or Reporting Job by Enterprise Tools
cmdjsp.jsp (or similar variants) within the web root to facilitate status checks, log collection, or remote command execution during nightly maintenance windows./backup/reports/, /logs/temp/) and restrict detection to business hours only if the tool runs exclusively after 6:00 PM. Alternatively, whitelist the specific Service Account (e.g., svc-backup-agent) that performs these writes.CI/CD Pipeline Deployment Artifacts
cmdjsp.jsp to the staging environment as part of a smoke test suite before promoting it to production. This often occurs in ephemeral containers or temporary build directories.10.20.30.x). Additionally, filter out events where the file modification timestamp falls within a known deployment window defined in the orchestration tool’s schedule.Legacy Application Maintenance by DevOps Administrators
cmdjsp.jsp as a standard utility