Malicious Exchange or SharePoint Worker Process Spawning Command Shell from Web Shell (via process_creation)

PremiumReviewedSigma · High · v1
Product
windows
Category
process_creation
Author
HuntRule
Published
2026-08-13
Updated
2026-08-28

ATT&CK techniques

Execution → Persistence
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Priv Esc

  5. Defense Evasion

  6. Cred Access

  7. Discovery

  8. Lateral Movement

  9. Collection

  10. C2

  11. Exfiltration

  12. Impact

What it detects

This rule detects the IIS worker process w3wp.exe spawning command shells or the net utility on on-premises Exchange or SharePoint servers, the web-shell execution behavior these attacks use after deploying pages such as getidtoken.aspx or signout.aspx. Adversaries drop web shells into OWA auth and LAYOUTS directories to run commands in the server context, so command interpreters descending from w3wp indicate server-side compromise.

Related detections9 linkedT1505.003 — drag to rearrange
Suspicious Scheduled Task Running PowerShell Every Minute (via process_creation)
Malicious Script Host Spawning PowerShell With Invoke-Expression (via process_creation)
Hidden PowerShell Archive Extraction via ExtractToDirectory
CastleLoader ClickFix PowerShell Hex Decode and Re-Execution
Possible Citrix ShareFile Unauthenticated Upload Path Traversal Webshell (CVE-2023-24489) (via webserver)
Possible Unauthenticated Admin Creation in Dynamicweb CVE-2022-25369
Possible DotCMS Path Traversal Webshell Upload via content API CVE-2022-26352
Possible Avaya Aura Device Services WebDAV PHP Webshell Upload via PhoneBackup (via webserver)
Possible DotCMS Arbitrary File Upload and JSP Webshell Drop via api content (via webserver)
Malicious Exchange or SharePoint Worker Process Spawning Command Shell from Web Shell (via process_creation)
Pivot detection · T1505.003 · 9 related

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.