Windows Webshell Recon Command-Line Keywords via Web Server Processes

Flags Windows process chains where web server parents spawn reconnaissance- and execution-related command lines indicative of webshell activity.

FreeReviewedSigma · High · v1
Product
windows
Category
process_creation
Author
Florian Roth (Nextron Systems), Jonhnathan Ribeiro, Anton Kutepov, oscd.community, Chad Hudson, Matt Anderson (SigmaHQ), DRL 1.1
Published
2017-01-01
Updated
2026-07-30

ATT&CK techniques

Persistence → Discovery
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Priv Esc

  6. Defense Evasion

  7. Cred Access

  8. Lateral Movement

  9. Collection

  10. C2

  11. Exfiltration

  12. Impact

What it detects

This rule identifies process creation on Windows where a web server parent process (e.g., w3wp.exe, php-cgi.exe, nginx.exe) is followed by command-line activity containing specific reconnaissance and execution patterns. Attackers commonly use webshells to run additional discovery commands and download or execute payloads, so the command-line keywords and suspicious child processes provide key behavioral signals. The detection relies on process creation telemetry with ParentImage/Image/OriginalFileName and CommandLine fields to match both the hosting context and the follow-on reconnaissance indicators.

Related detections9 linkedT1505.003 — drag to rearrange
Windows Process Creation: China Chopper Webshell Command Pattern via W3WP
Windows Webserver Parent Process Launching Credential Dumping and Exfiltration Commands
Suspicious SimpleHelp Remote Access Client Spawning Discovery Commands (via process_creation)
Cisco AAA discovery via show/dir commands
Suspicious SD-WAN Compromise JSP Webshell Access
Malicious AquaShell Webshell Access on Cisco Secure Email Gateway by UAT-9686
Suspicious Domain Controller Enumeration via Nltest by DeadLock Ransomware
Malicious IIS Worker Process Spawning Command Shell Reconnaissance
Malicious StyleSmuggler (CVE-2026-75650) Web Shell Dropped In Magento Product Image Cache (via file_event)
Windows Webshell Recon Command-Line Keywords via Web Server Processes
Pivot detection · T1505.003 · 9 related

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.