This detection identifies adversaries deploying a “Safe mode” web shell named breaker.php to establish persistence and execute commands on compromised Azure web servers. Proactive hunting for this specific artifact is critical in Azure Sentinel because such shells often serve as an initial foothold for lateral movement, allowing attackers to evade standard file integrity checks by leveraging safe mode configurations.
rule webshell_Safe_mode_breaker {
meta:
description = "Web Shell - file Safe mode breaker.php"
license = "Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE"
author = "Florian Roth (Nextron Systems)"
date = "2014/01/28"
score = 70
hash = "5bd07ccb1111950a5b47327946bfa194"
id = "393e738a-b4c2-5630-a55f-c3caee4ff75e"
strings:
$s5 = "preg_match(\"/SAFE\\ MODE\\ Restriction\\ in\\ effect\\..*whose\\ uid\\ is("
$s6 = "$path =\"{$root}\".((substr($root,-1)!=\"/\") ? \"/\" : NULL)."
condition:
1 of them
}
This YARA rule can be deployed in the following contexts:
This rule contains 3 string patterns in its detection logic.
Here are 5 specific false positive scenarios for the Web Shell - file Safe mode breaker.php detection rule, including tailored filters and exclusions:
Scenario: DevOps Deployment via CI/CD Pipeline
Safe mode breaker.php in the /var/www/html/includes/ directory as part of the standard application bundle before the web server restarts.github-actions-runner, jenkins-agent, or docker-entrypoint.sh. Additionally, filter by the specific deployment directory path (e.g., /var/www/html/includes/) to ensure only files created within known application folders are ignored.Scenario: Scheduled Maintenance Script for Legacy Module
maintenance_runner.py) executes at 02:00 AM to refresh legacy module configurations. This script regenerates the Safe mode breaker.php file to reset session states for the “Safe Mode” feature of an internal HR portal.python3 or cron and the user context is the dedicated service account svc_hr_maintenance.Scenario: Automated Backup and Restoration Routine