Cross-source coverage
T1505 / ATT&CK
Server Software Component
173 rules · 166 families across 12 sources.
9 deprecated hidden · include
From MITRE ATT&CK 19.2
Adversaries may abuse legitimate extensible development features of servers to establish persistent access to systems. Enterprise server applications may include features that allow developers to write and install software or scripts to extend the functionality of the main application. Adversaries may install malicious components to extend and abuse server applications.
- Tactics
- Persistence
- Platforms
- Windows · Linux · macOS · Network Devices · ESXi
- Telemetry
-
WinEventLog:SecurityWinEventLog:SysmonWinEventLog:Applicationauditd:SYSCALLlinux:syslogNSM:Flowmacos:unifiedlogesxi:hostdesxi:vmkernel
How MITRE says to detect it DET0547
Detection Strategy for T1505 - Server Software Component
Windows Analytic 1507
Installation of malicious IIS/Apache/SQL server modules that later execute command-line interpreters or establish outbound connections.
WinEventLog:SecurityEventCode=4698WinEventLog:SysmonEventCode=1WinEventLog:ApplicationUnusual DLL/plugin registration for IIS/SQL/Apache or unexpected error logs
Linux Analytic 1508
Abuse of extensible server modules (e.g., Apache, Nginx, Tomcat) to load rogue plugins that initiate bash, connect to C2, or spawn reverse shells.
auditd:SYSCALLexecvelinux:syslogModule registration or stacktrace logs indicating segmentation faults or unknown module errorsNSM:FlowOutbound connections from web server binaries (apache2, nginx, php-fpm) to unknown external IPs
macOS Analytic 1509
Malicious use of webserver plugins (e.g., for nginx, PHP, Node.js) that execute AppleScript or open network sockets.
macos:unifiedlogScript interpreter invoked by nginx/apache worker processmacos:unifiedlogWeb server process initiating outbound TCP connections not tied to normal server traffic
ESXi Analytic 1510
Use of ESXi web interface plugins or vSphere extensions to embed persistent malicious scripts or services.
esxi:hostdNew extension/module install with unknown vendor IDesxi:vmkernelUnexpected restarts of management agents or shell access
Sub-techniques with coverage
Counted in the 173 above — a rule tagged a sub-technique covers this technique too.
SigmaHQ/sigma
47 rules| Detection | Severity | Format |
|---|---|---|
| Certificate Request Export to Exchange Webserver | Critical | Sigma |
| CVE-2021-40539 Zoho ManageEngine ADSelfService Plus Exploit | Critical | Sigma |
| Mailbox Export to Exchange Webserver | Critical | Sigma |
| Oracle WebLogic Exploit | Critical | Sigma |
| Solarwinds SUPERNOVA Webshell Access | Critical | Sigma |
| Webshell Remote Command Execution | Critical | Sigma |
| WordPress Wp2shell Webshell Plugin Access | Critical | Sigma |
| Antivirus - Web Shell Detection Signature | High | Sigma |
| Chopper Webshell Process Pattern | High | Sigma |
| Commvault QOperation Path Traversal Webshell Drop (CVE-2025-57790) | High | Sigma |
+ 37 more from SigmaHQ/sigma → showing the 10 highest-severity
splunk/security_content
39 rules| Detection | Severity | Format |
|---|---|---|
| Cisco Configuration Archive Logging Analysis | Undefined | SPL |
| Cisco Secure Firewall - Privileged Command Execution via HTTP | Undefined | SPL |
| Confluence Unauthenticated Remote Code Execution CVE-2022-26134 | Undefined | SPL |
| Detect Exchange Web Shell | Undefined | SPL |
| ESXi Malicious VIB Forced Install | Undefined | SPL |
| Exploit Public Facing Application via Apache Commons Text | Undefined | SPL |
| Linux Suspicious Redis Activity | Undefined | SPL |
| MS Exchange Mailbox Replication service writing Active Server Pages | Undefined | SPL |
| Spring4Shell Payload URL Request | Undefined | SPL |
| Supernova Webshell | Undefined | SPL |
+ 29 more from splunk/security_content → showing the 10 highest-severity
Emerging Threats Open
33 rules · 26 families| Detection | Severity | Format |
|---|---|---|
| ET ATTACK_RESPONSE Possible arp command output via HTTP (Linux Style) | High | Suricata |
| ET ATTACK_RESPONSE Possible arp command output via HTTP (MacOS Style) | High | Suricata |
| ET ATTACK_RESPONSE Possible arp command output via HTTP (Windows Style) | High | Suricata |
| ET ATTACK_RESPONSE Possible /etc/shadow via HTTP M1 4 variants | High | Suricata |
| ET ATTACK_RESPONSE Possible /etc/shadow via HTTP M2 4 variants | High | Suricata |
| ET ATTACK_RESPONSE Possible /etc/shadow via HTTP M3 4 variants | High | Suricata |
| ET ATTACK_RESPONSE Possible /etc/shadow via HTTP M4 4 variants | High | Suricata |
| ET ATTACK_RESPONSE Possible hosts File Output via HTTP (Linux Style) | High | Suricata |
| ET ATTACK_RESPONSE Possible hosts File Output via HTTP (Windows Style) | High | Suricata |
| ET ATTACK_RESPONSE Possible WebShell Upload Attempt via Directory Traversal M1 2 variants | High | Suricata |
+ 23 more from Emerging Threats Open → showing the 10 highest-severity
elastic/detection-rules
27 rules| Detection | Severity | Format |
|---|---|---|
| Microsoft Exchange Worker Spawning Suspicious Processes | High | Elastic TOML |
| MySQL User-Defined Function Injection | High | Elastic TOML |
| Potential SAP NetWeaver Exploitation | High | Elastic TOML |
| Potential SAP NetWeaver WebShell Creation | High | Elastic TOML |
| Potential Webshell Deployed via Apache Struts CVE-2023-50164 Exploitation | High | Elastic TOML |
| ScreenConnect Server Spawning Suspicious Processes | High | Elastic TOML |
| Web Server Exploitation Detected via Defend for Containers | High | Elastic TOML |
| Web Server Potential SQL Injection Request | High | Elastic TOML |
| Web Shell Detection: Script Process Child of Common Web Processes | High | Elastic TOML |
| Windows Server Update Service Spawning Suspicious Processes | High | Elastic TOML |
+ 17 more from elastic/detection-rules → showing the 10 highest-severity
elastic/protections-artifacts
8 rules| Detection | Severity | Format |
|---|---|---|
| Payload Downloaded via Curl or Wget by Web Server | Undefined | Elastic TOML |
| Payload Execution by Node.js Web Server | Undefined | Elastic TOML |
| Payload Execution by Web Server | Undefined | Elastic TOML |
| Potential Remote Code Execution via Database Server | Undefined | Elastic TOML |
| Potential Remote Code Execution via URL Encoded Payload | Undefined | Elastic TOML |
| Suspicious Execution via Microsoft Exchange Transport Agent | Undefined | Elastic TOML |
| Suspicious File Creation via Web Server | Undefined | Elastic TOML |
| Suspicious Web Server Child Process | Undefined | Elastic TOML |
socfortress/Wazuh-Rules
5 rules| Detection | Severity | Format |
|---|---|---|
| Sysmon - Event 1: Process creation · AppCmd Module Install (T1505.004) | High | Wazuh XML |
| Sysmon - Event 1: Process creation · Exchange Transport Agent Installation (T1505.002) | High | Wazuh XML |
| Sysmon - Event 1: Process creation · PowerShell IIS Module (T1505.004) | High | Wazuh XML |
| Sysmon - Event 1: Process creation · XCopy Archiving (T1505.003) | High | Wazuh XML |
| Sysmon - Event 7: Image loaded by · DLL Load in IIS (T1505.004) | High | Wazuh XML |
Wazuh Core Ruleset
4 rules| Detection | Severity | Format |
|---|---|---|
| file. | Medium | Wazuh XML |
| Simple shell.php command execution. | Medium | Wazuh XML |
| Squid: Attempt to access a worm/trojan related site. | Medium | Wazuh XML |
| TimThumb backdoor access attempt. | Medium | Wazuh XML |
chronicle/detection-rules
4 rules| Detection | Severity | Format |
|---|---|---|
| ttp_windows_sharepoint_cve_2025_53770_webshell_succeeded | Critical | YARA-L |
| ttp_windows_sharepoint_cve_2025_53770_webshell_attempted | High | YARA-L |
| ttp_windows_suspicious_filewrites_to_sharepoint_layouts | High | YARA-L |
| ttp_windows_webserver_process_potential_webshell_execution | Medium | YARA-L |
Bert-JanP/Hunting-Queries-Detection-Rules
2 rules| Detection | Severity | Format |
|---|---|---|
| MITRE ATT&CK Mapping | Undefined | KQL |
| Possible webshell on the endpoint | Undefined | KQL |
falcosecurity/rules
2 rules| Detection | Severity | Format |
|---|---|---|
| Web Server Spawned Shell | Critical | Falco YAML |
| Launch Package Management Process in Container | High | Falco YAML |
Azure/Azure-Sentinel
1 rule| Detection | Severity | Format |
|---|---|---|
| GitHub OAuth App Restrictions Disabled | Undefined | KQL |
panther-labs/panther-analysis
1 rule| Detection | Severity | Format |
|---|---|---|
| Slack App Added | Medium | Panther Python |