MITRE ATT&CK coverage
| Tactic | Techniques |
|---|---|
| Persistence |
Rule body
id: f3245aa1-1ca1-471c-a0b7-97ea6b791d5d
name: Corelight - Possible Webshell
description: |
'Detects post requests to unusual extensions.'
severity: Medium
status: Available
requiredDataConnectors:
- connectorId: Corelight
dataTypes:
- Corelight_v2_http
- corelight_http
queryFrequency: 1h
queryPeriod: 1h
triggerOperator: gt
triggerThreshold: 0
tactics:
- Persistence
relevantTechniques:
- T1505
query: |
corelight_http
| where method in~ ('POST', 'PUT')
| where toint(status_code) between (200 .. 299)
| where request_body_len != 0 or response_body_len != 0
| extend fe = extract(@'.*(\.\w+)$', 1, uri)
| where fe in~ ('.jpg', '.jpeg', '.gif', '.png', '.icon', '.ico', '.xml', '.swf', '.svg', '.ppt', '.pttx', '.doc', '.docx', '.rtf', '.pdf', '.tif', '.zip', '.mov')
entityMappings:
- entityType: IP
fieldMappings:
- identifier: Address
columnName: id_orig_h
version: 2.1.0
kind: Scheduled
Stages and Predicates
Stage 1: source
corelight_http
Stage 2: where
| where method in~ ('POST', 'PUT')
Stage 3: where
| where toint(status_code) between (200 .. 299)
Stage 4: where
| where request_body_len != 0 or response_body_len != 0
Stage 5: extend
| extend fe = extract(@'.*(\.\w+)$', 1, uri)
Stage 6: where
| where fe in~ ('.jpg', '.jpeg', '.gif', '.png', '.icon', '.ico', '.xml', '.swf', '.svg', '.ppt', '.pttx', '.doc', '.docx', '.rtf', '.pdf', '.tif', '.zip', '.mov')
Indicators
These rows show field, operator, and value matches.
| Field | Kind | Values | Search |
|---|---|---|---|
fe | in |
| field:"fe" kind:in |
method | in |
| field:"method" kind:in |
request_body_len | ne |
| field:"request_body_len" kind:ne value:"0" |
response_body_len | ne |
| field:"response_body_len" kind:ne value:"0" |
Output fields
These fields are emitted when the rule matches.
| Field | Source |
|---|---|
fe | extend |