Windows Webserver Parent Process Launching Credential Dumping and Exfiltration Commands

Flags web server processes spawning child commands consistent with credential dumping, exfiltration, and privilege changes.

FreeReviewedSigma · High · v1
Product
windows
Category
process_creation
Author
Florian Roth (Nextron Systems) (SigmaHQ), DRL 1.1
Published
2022-03-17
Updated
2026-07-30

ATT&CK techniques

Persistence → Discovery
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Priv Esc

  6. Defense Evasion

  7. Cred Access

  8. Lateral Movement

  9. Collection

  10. C2

  11. Exfiltration

  12. Impact

What it detects

This rule identifies Windows process creation events where a common web server parent process (Caddy, Apache httpd, Nginx, php-cgi, IIS w3wp, or Tomcat Java) spawns a child process whose command line matches patterns used for credential dumping, archive-based exfiltration, local administrator changes, or AD/service reconnaissance. This matters because attackers commonly use web shells under web-facing processes to blend malicious activity with legitimate server execution. The detection relies on Windows process creation telemetry, specifically the parent image, child image, and command-line substrings captured in event logs.

Related detections9 linkedT1505.003 — drag to rearrange
Windows Process Creation: China Chopper Webshell Command Pattern via W3WP
Windows Webshell Recon Command-Line Keywords via Web Server Processes
Suspicious SimpleHelp Remote Access Client Spawning Discovery Commands (via process_creation)
Cisco AAA discovery via show/dir commands
Suspicious SD-WAN Compromise JSP Webshell Access
Malicious AquaShell Webshell Access on Cisco Secure Email Gateway by UAT-9686
Suspicious Domain Controller Enumeration via Nltest by DeadLock Ransomware
Malicious IIS Worker Process Spawning Command Shell Reconnaissance
Malicious StyleSmuggler (CVE-2026-75650) Web Shell Dropped In Magento Product Image Cache (via file_event)
Windows Webserver Parent Process Launching Credential Dumping and Exfiltration Commands
Pivot detection · T1505.003 · 9 related

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.