Suspicious Serv-U Process Pattern
Description
Detects a suspicious process pattern which could be a sign of an exploited Serv-U service
Query · sigma
selection: ParentImage|endswith: \Serv-U.exe Image|endswith: - \cmd.exe - \powershell.exe - \pwsh.exe - \wscript.exe - \cscript.exe - \sh.exe - \bash.exe - \schtasks.exe - \regsvr32.exe - \wmic.exe - \mshta.exe - \rundll32.exe - \msiexec.exe - \forfiles.exe - \scriptrunner.exe condition: selection
Known false positives
- Legitimate uses in which users or programs use the SSH service of Serv-U for remote command execution