Linux auditd: Webshell Remote Command Execution via execve/execveat (euid=33)

Alerts on execve/execveat executions by the web server user, consistent with potential webshell command execution.

FreeReviewedSigma · Critical · v3
Product
linux
Service
auditd
Author
Ilyas Ochkov, Beyu Denis, oscd.community (SigmaHQ), DRL 1.1
Published
2019-10-12
Updated
2026-07-31

ATT&CK techniques

Persistence
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Priv Esc

  6. Defense Evasion

  7. Cred Access

  8. Discovery

  9. Lateral Movement

  10. Collection

  11. C2

  12. Exfiltration

  13. Impact

What it detects

This rule flags processes executed by a specific web server user that invoke execve or execveat, consistent with remote command execution from a web application or web shell. Attackers rely on process execution to run arbitrary payloads under the web server’s privileges, enabling persistence and further compromise. It relies on Linux auditd syscall telemetry for execve/execveat events and matches the effective user ID of the web server account.

Related detections9 linkedT1505.003 — drag to rearrange
Suspicious SD-WAN Compromise JSP Webshell Access
Malicious AquaShell Webshell Access on Cisco Secure Email Gateway by UAT-9686
Malicious IIS Worker Process Spawning Command Shell Reconnaissance
Malicious StyleSmuggler (CVE-2026-75650) Web Shell Dropped In Magento Product Image Cache (via file_event)
Suspicious Web Shell File Written to IIS wwwroot Directory
Possible Citrix ShareFile Unauthenticated Upload Path Traversal Webshell (CVE-2023-24489) (via webserver)
Possible Unauthenticated Admin Creation in Dynamicweb CVE-2022-25369
Possible DotCMS Path Traversal Webshell Upload via content API CVE-2022-26352
Possible Avaya Aura Device Services WebDAV PHP Webshell Upload via PhoneBackup (via webserver)
Linux auditd: Webshell Remote Command Execution via execve/execveat (euid=33)
Pivot detection · T1505.003 · 9 related

Changelog

v3
  1. v3
    Candidate ingested via manual entry.2026-07-31
  2. v2
    Candidate ingested via manual entry.2026-07-31
  3. v1
    No changelog recorded for this version.2026-07-30

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.