This detection identifies adversaries deploying a cmdjsp.jsp web shell to establish persistent command-and-control channels for executing remote commands on compromised web servers. Proactively hunting for this artifact in Azure Sentinel is critical because JSP-based shells often evade standard file integrity monitoring and can serve as the initial foothold for lateral movement or data exfiltration within cloud-hosted applications.
rule webshell_jsp_cmdjsp {
meta:
description = "Web Shell - file cmdjsp.jsp"
license = "Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE"
author = "Florian Roth (Nextron Systems)"
date = "2014/01/28"
score = 70
hash = "b815611cc39f17f05a73444d699341d4"
id = "393e738a-b4c2-5630-a55f-c3caee4ff75e"
strings:
$s5 = "<FORM METHOD=GET ACTION='cmdjsp.jsp'>" fullword
condition:
all of them
}
This YARA rule can be deployed in the following contexts:
This rule contains 1 string patterns in its detection logic.
Here are 5 specific false positive scenarios for the Web Shell - file cmdjsp.jsp detection rule, including suggested filters and exclusions:
Scenario: Automated Deployment by CI/CD Pipeline
cmdjsp.jsp (a utility page for internal health checks) to the Tomcat web root as part of the artifact bundle.svc-jenkins-deploy) and the process name matches the deployment agent (e.g., java.exe running a Maven or Gradle build).Scenario: Scheduled Maintenance Health Check
cmdjsp.jsp to verify server connectivity and database status before the business day begins. This file is part of a standard monitoring suite used by the IT Operations team.svchost.exe or taskeng.exe, specifically targeting the known path \webapps\monitoring\cmdjsp.jsp.Scenario: Administrator Manual Configuration via Remote Desktop
cmdjsp.jsp file from a local repository to the server’s webapps directory using a standard copy command or GUI drag-and-drop.