Malicious Command Execution Spawned by SharePoint w3wp Worker Process

PremiumReviewedSigma · High · v1
Product
windows
Category
process_creation
Author
HuntRule
Published
2026-09-24
Updated
2026-09-24

ATT&CK techniques

Execution → Persistence
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Priv Esc

  5. Defense Evasion

  6. Cred Access

  7. Discovery

  8. Lateral Movement

  9. Collection

  10. C2

  11. Exfiltration

  12. Impact

What it detects

This rule detects the IIS worker process w3wp.exe spawning cmd.exe or a scripting host, behavior seen when ToolShell webshells such as spinstall0.aspx execute operating system commands on compromised SharePoint servers. A web server worker launching a command interpreter is a hallmark of webshell-driven remote command execution following exploitation.

Related detections9 linkedT1059.003 — drag to rearrange
Malicious Shell Spawned by SharePoint Worker Process w3wp
Malicious IIS Worker Process Spawning Command Shell via process_creation
Suspicious cmd.exe execution from w3wp.exe tied to CentreStack portal.config (Windows process creation)
Suspicious Ballistic Bobcat Backdoor Command Output Redirection via Cmd (via process_creation)
Suspicious ToolShell Webshell Written to SharePoint Layouts Directory
Suspicious Webshell Deployment in DNN DesktopModules Directory
Suspicious PIF Payload Assembly via copy /b Binary Concatenation
Suspicious DarkGate AutoIt3 Script Execution from C Test Directory
Suspicious AdsExhaust Batch Persistence in AppData wespmail Folder
Malicious Command Execution Spawned by SharePoint w3wp Worker Process
Pivot detection · T1059.003 · 9 related

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.