Suspicious Child Process of SAP NetWeaver


Description

Detects suspicious child processes spawned by SAP NetWeaver that could indicate potential exploitation of vulnerability that allows arbitrary execution via webshells such as CVE-2025-31324.

Query · sigma

selection_parent_img:
  ParentImage|contains:
  - \j2ee\cluster\apps\sap.com\irj\servlet_jsp\irj\work
  - \j2ee\cluster\apps\sap.com\irj\servlet_jsp\irj\root
selection_current_dict:
  CurrentDirectory|contains:
  - \j2ee\cluster\apps\sap.com\irj\servlet_jsp\irj\work
  - \j2ee\cluster\apps\sap.com\irj\servlet_jsp\irj\root
selection_child:
  Image|endswith:
  - \cmd.exe
  - \powershell.exe
  - \powershell_ise.exe
  - \pwsh.exe
  - \wscript.exe
  - \cscript.exe
  - \regsvr32.exe
  - \rundll32.exe
  - \mshta.exe
  - \certutil.exe
  - \bitsadmin.exe
  - \python.exe
condition: (selection_parent_img or selection_current_dict) and selection_child

Known false positives

  • Legitimate administrative activities such as software updates
Raw source Suspicious Child Process of SAP NetWeaver · Sigma
Esc
Published by SigmaHQ/sigma ↗, licensed under Detection Rule License 1.1 ↗. Reproduced here unmodified.
title: Suspicious Child Process of SAP NetWeaver
id: 5b304bcb-ac33-49d0-87af-fa1b3ca94333
status: experimental
description: |
    Detects suspicious child processes spawned by SAP NetWeaver that could indicate potential
    exploitation of vulnerability that allows arbitrary execution via webshells such as CVE-2025-31324.
author: Elastic (idea), Swachchhanda Shrawan Poudel (Nextron Systems)
date: 2025-04-28
tags:
    - attack.execution
    - attack.initial-access
    - attack.t1190
    - attack.persistence
    - attack.t1059.003
    - cve.2025-31324
    - detection.emerging-threats
references:
    - https://reliaquest.com/blog/threat-spotlight-reliaquest-uncovers-vulnerability-behind-sap-netweaver-compromise/
    - https://onapsis.com/blog/active-exploitation-of-sap-vulnerability-cve-2025-31324/
logsource:
    category: process_creation
    product: windows
detection:
    selection_parent_img:
        ParentImage|contains:
            - '\j2ee\cluster\apps\sap.com\irj\servlet_jsp\irj\work'
            - '\j2ee\cluster\apps\sap.com\irj\servlet_jsp\irj\root'
    selection_current_dict:
        CurrentDirectory|contains:
            - '\j2ee\cluster\apps\sap.com\irj\servlet_jsp\irj\work'
            - '\j2ee\cluster\apps\sap.com\irj\servlet_jsp\irj\root'
    selection_child:
        Image|endswith:
            - '\cmd.exe'
            - '\powershell.exe'
            - '\powershell_ise.exe'
            - '\pwsh.exe'
            - '\wscript.exe'
            - '\cscript.exe'
            - '\regsvr32.exe'
            - '\rundll32.exe'
            - '\mshta.exe'
            - '\certutil.exe'
            - '\bitsadmin.exe'
            - '\python.exe'
    condition: (selection_parent_img or selection_current_dict) and selection_child
falsepositives:
    - Legitimate administrative activities such as software updates
level: medium

Detection rules belong to the projects that publish them and remain under their own licenses. This site indexes and links to them; it claims no rights in them.