Suspicious cmd.exe execution from w3wp.exe tied to CentreStack portal.config (Windows process creation)

Alerts when w3wp.exe launches cmd.exe and its command line references \portal\portal.config, suggesting possible IIS app exploitation.

FreeReviewedSigma · High · v5
Product
windows
Category
process_creation
Author
Jason Rathbun (Blackpoint Cyber) (SigmaHQ), DRL 1.1
Published
2025-04-17
Updated
2026-07-31

ATT&CK techniques

Execution → Persistence
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Priv Esc

  5. Defense Evasion

  6. Cred Access

  7. Discovery

  8. Lateral Movement

  9. Collection

  10. C2

  11. Exfiltration

  12. Impact

What it detects

This rule identifies process creation events where cmd.exe is spawned and the parent process is w3wp.exe. It further scopes the match to cases where the parent command line contains a CentreStack portal.config path, suggesting the portal service triggered command shell execution. Such behavior is high risk because it can indicate web-service exploitation leading to OS command execution. Telemetry required includes Windows process creation logs with parent process image/command line and the spawned process image.

Related detections9 linkedT1505.003 — drag to rearrange
Malicious IIS Worker Process Spawning Command Shell via process_creation
Suspicious SD-WAN Compromise JSP Webshell Access
Malicious AquaShell Webshell Access on Cisco Secure Email Gateway by UAT-9686
Malicious IIS Worker Process Spawning Command Shell Reconnaissance
Malicious StyleSmuggler (CVE-2026-75650) Web Shell Dropped In Magento Product Image Cache (via file_event)
Suspicious Web Shell File Written to IIS wwwroot Directory
Suspicious IP Release and Renew via Minimized cmd During Driver Install
Possible Citrix ShareFile Unauthenticated Upload Path Traversal Webshell (CVE-2023-24489) (via webserver)
Possible Unauthenticated Admin Creation in Dynamicweb CVE-2022-25369
Suspicious cmd.exe execution from w3wp.exe tied to CentreStack portal.config (Windows process creation)
Pivot detection · T1505.003 · 9 related

Changelog

v5
  1. v5
    Candidate ingested via manual entry.2026-07-31
  2. v4
    Candidate ingested via manual entry.2026-07-31
  3. v3
    Candidate ingested via manual entry.2026-07-31
  4. v2
    Candidate ingested via manual entry.2026-07-31
  5. v1
    No changelog recorded for this version.2026-07-30

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.