Cross-source coverage

T1505 / ATT&CK

Server Software Component

173 rules · 166 families across 12 sources.

9 deprecated hidden · include

From MITRE ATT&CK 19.2

Adversaries may abuse legitimate extensible development features of servers to establish persistent access to systems. Enterprise server applications may include features that allow developers to write and install software or scripts to extend the functionality of the main application. Adversaries may install malicious components to extend and abuse server applications.

Tactics
Persistence
Platforms
Windows · Linux · macOS · Network Devices · ESXi
Telemetry
WinEventLog:SecurityWinEventLog:SysmonWinEventLog:Applicationauditd:SYSCALLlinux:syslogNSM:Flowmacos:unifiedlogesxi:hostdesxi:vmkernel

How MITRE says to detect it DET0547

Detection Strategy for T1505 - Server Software Component

Windows Analytic 1507

Installation of malicious IIS/Apache/SQL server modules that later execute command-line interpreters or establish outbound connections.

  • WinEventLog:Security EventCode=4698
  • WinEventLog:Sysmon EventCode=1
  • WinEventLog:Application Unusual DLL/plugin registration for IIS/SQL/Apache or unexpected error logs

Linux Analytic 1508

Abuse of extensible server modules (e.g., Apache, Nginx, Tomcat) to load rogue plugins that initiate bash, connect to C2, or spawn reverse shells.

  • auditd:SYSCALL execve
  • linux:syslog Module registration or stacktrace logs indicating segmentation faults or unknown module errors
  • NSM:Flow Outbound connections from web server binaries (apache2, nginx, php-fpm) to unknown external IPs

macOS Analytic 1509

Malicious use of webserver plugins (e.g., for nginx, PHP, Node.js) that execute AppleScript or open network sockets.

  • macos:unifiedlog Script interpreter invoked by nginx/apache worker process
  • macos:unifiedlog Web server process initiating outbound TCP connections not tied to normal server traffic

ESXi Analytic 1510

Use of ESXi web interface plugins or vSphere extensions to embed persistent malicious scripts or services.

  • esxi:hostd New extension/module install with unknown vendor ID
  • esxi:vmkernel Unexpected restarts of management agents or shell access

Sub-techniques with coverage

Counted in the 173 above — a rule tagged a sub-technique covers this technique too.


SigmaHQ/sigma

47 rules
Detection Severity Format
Certificate Request Export to Exchange Webserver Critical Sigma
CVE-2021-40539 Zoho ManageEngine ADSelfService Plus Exploit Critical Sigma
Mailbox Export to Exchange Webserver Critical Sigma
Oracle WebLogic Exploit Critical Sigma
Solarwinds SUPERNOVA Webshell Access Critical Sigma
Webshell Remote Command Execution Critical Sigma
WordPress Wp2shell Webshell Plugin Access Critical Sigma
Antivirus - Web Shell Detection Signature High Sigma
Chopper Webshell Process Pattern High Sigma
Commvault QOperation Path Traversal Webshell Drop (CVE-2025-57790) High Sigma

+ 37 more from SigmaHQ/sigma → showing the 10 highest-severity

splunk/security_content

39 rules
Detection Severity Format
Cisco Configuration Archive Logging Analysis Undefined SPL
Cisco Secure Firewall - Privileged Command Execution via HTTP Undefined SPL
Confluence Unauthenticated Remote Code Execution CVE-2022-26134 Undefined SPL
Detect Exchange Web Shell Undefined SPL
ESXi Malicious VIB Forced Install Undefined SPL
Exploit Public Facing Application via Apache Commons Text Undefined SPL
Linux Suspicious Redis Activity Undefined SPL
MS Exchange Mailbox Replication service writing Active Server Pages Undefined SPL
Spring4Shell Payload URL Request Undefined SPL
Supernova Webshell Undefined SPL

+ 29 more from splunk/security_content → showing the 10 highest-severity

Emerging Threats Open

33 rules · 26 families
Detection Severity Format
ET ATTACK_RESPONSE Possible arp command output via HTTP (Linux Style) High Suricata
ET ATTACK_RESPONSE Possible arp command output via HTTP (MacOS Style) High Suricata
ET ATTACK_RESPONSE Possible arp command output via HTTP (Windows Style) High Suricata
ET ATTACK_RESPONSE Possible /etc/shadow via HTTP M1 4 variants High Suricata
ET ATTACK_RESPONSE Possible /etc/shadow via HTTP M2 4 variants High Suricata
ET ATTACK_RESPONSE Possible /etc/shadow via HTTP M3 4 variants High Suricata
ET ATTACK_RESPONSE Possible /etc/shadow via HTTP M4 4 variants High Suricata
ET ATTACK_RESPONSE Possible hosts File Output via HTTP (Linux Style) High Suricata
ET ATTACK_RESPONSE Possible hosts File Output via HTTP (Windows Style) High Suricata
ET ATTACK_RESPONSE Possible WebShell Upload Attempt via Directory Traversal M1 2 variants High Suricata

+ 23 more from Emerging Threats Open → showing the 10 highest-severity

elastic/detection-rules

27 rules
Detection Severity Format
Microsoft Exchange Worker Spawning Suspicious Processes High Elastic TOML
MySQL User-Defined Function Injection High Elastic TOML
Potential SAP NetWeaver Exploitation High Elastic TOML
Potential SAP NetWeaver WebShell Creation High Elastic TOML
Potential Webshell Deployed via Apache Struts CVE-2023-50164 Exploitation High Elastic TOML
ScreenConnect Server Spawning Suspicious Processes High Elastic TOML
Web Server Exploitation Detected via Defend for Containers High Elastic TOML
Web Server Potential SQL Injection Request High Elastic TOML
Web Shell Detection: Script Process Child of Common Web Processes High Elastic TOML
Windows Server Update Service Spawning Suspicious Processes High Elastic TOML

+ 17 more from elastic/detection-rules → showing the 10 highest-severity

elastic/protections-artifacts

8 rules
Detection Severity Format
Payload Downloaded via Curl or Wget by Web Server Undefined Elastic TOML
Payload Execution by Node.js Web Server Undefined Elastic TOML
Payload Execution by Web Server Undefined Elastic TOML
Potential Remote Code Execution via Database Server Undefined Elastic TOML
Potential Remote Code Execution via URL Encoded Payload Undefined Elastic TOML
Suspicious Execution via Microsoft Exchange Transport Agent Undefined Elastic TOML
Suspicious File Creation via Web Server Undefined Elastic TOML
Suspicious Web Server Child Process Undefined Elastic TOML

socfortress/Wazuh-Rules

5 rules
Detection Severity Format
Sysmon - Event 1: Process creation · AppCmd Module Install (T1505.004) High Wazuh XML
Sysmon - Event 1: Process creation · Exchange Transport Agent Installation (T1505.002) High Wazuh XML
Sysmon - Event 1: Process creation · PowerShell IIS Module (T1505.004) High Wazuh XML
Sysmon - Event 1: Process creation · XCopy Archiving (T1505.003) High Wazuh XML
Sysmon - Event 7: Image loaded by · DLL Load in IIS (T1505.004) High Wazuh XML

Wazuh Core Ruleset

4 rules
Detection Severity Format
file. Medium Wazuh XML
Simple shell.php command execution. Medium Wazuh XML
Squid: Attempt to access a worm/trojan related site. Medium Wazuh XML
TimThumb backdoor access attempt. Medium Wazuh XML

chronicle/detection-rules

4 rules
Detection Severity Format
ttp_windows_sharepoint_cve_2025_53770_webshell_succeeded Critical YARA-L
ttp_windows_sharepoint_cve_2025_53770_webshell_attempted High YARA-L
ttp_windows_suspicious_filewrites_to_sharepoint_layouts High YARA-L
ttp_windows_webserver_process_potential_webshell_execution Medium YARA-L

Bert-JanP/Hunting-Queries-Detection-Rules

2 rules
Detection Severity Format
MITRE ATT&CK Mapping Undefined KQL
Possible webshell on the endpoint Undefined KQL

falcosecurity/rules

2 rules
Detection Severity Format
Web Server Spawned Shell Critical Falco YAML
Launch Package Management Process in Container High Falco YAML

Azure/Azure-Sentinel

1 rule
Detection Severity Format
GitHub OAuth App Restrictions Disabled Undefined KQL

panther-labs/panther-analysis

1 rule
Detection Severity Format
Slack App Added Medium Panther Python

Detection rules belong to the projects that publish them and remain under their own licenses. This site indexes and links to them; it claims no rights in them.