This detection rule identifies adversaries deploying a jshell.jsp web shell to establish persistent access and execute arbitrary commands on compromised web servers. A proactive hunt is essential in Azure Sentinel because this specific JSP file often indicates an early-stage post-exploitation foothold that can be leveraged for lateral movement or data exfiltration before broader network impact occurs.
rule webshell_jsp_jshell {
meta:
description = "Web Shell - file jshell.jsp"
license = "Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE"
author = "Florian Roth (Nextron Systems)"
date = "2014/01/28"
score = 70
hash = "124b22f38aaaf064cef14711b2602c06"
id = "393e738a-b4c2-5630-a55f-c3caee4ff75e"
strings:
$s0 = "kXpeW[\"" fullword
$s4 = "[7b:g0W@W<" fullword
$s5 = "b:gHr,g<" fullword
$s8 = "RhV0W@W<" fullword
$s9 = "S_MR(u7b" fullword
condition:
all of them
}
This YARA rule can be deployed in the following contexts:
This rule contains 5 string patterns in its detection logic.
Here are 5 specific false positive scenarios for the Web Shell - file jshell.jsp detection rule, including suggested filters and exclusions:
Scenario: Automated Deployment via CI/CD Pipeline
jshell.jsp is automatically copied to the /webapps/ROOT directory during every build cycle. This file acts as a lightweight diagnostic tool included in the base image, not an attacker-injected shell.jenkins-agent.exe, gitlab-runner) and the destination path matches the standard deployment directory (C:\Program Files\Apache Software Foundation\Tomcat\webapps\ROOT).Scenario: Scheduled Health Check by Monitoring Agent
jshell.jsp file in the application’s temp directory (/tmp or /temp) to execute a quick connectivity test before immediately deleting it.svc-monitoring) that are deleted within 60 seconds of creation, specifically targeting paths ending in \temp\jshell.jsp.Scenario: Administrator Manual Debugging Session