Detection rules › Sigma
Suspicious Child Process of SAP NetWeaver - Linux
Detects suspicious child processes spawned by SAP NetWeaver on Linux systems that could indicate potential exploitation of vulnerability that allows arbitrary execution via webshells such as CVE-2025-31324.
Known false positives
- Legitimate administrative activities such as software updates
MITRE ATT&CK coverage
| Tactic | Techniques |
|---|---|
| Initial Access | |
| Execution |
Telemetry coverage
| Platform | Record / event type |
|---|---|
| Linux | Event ID 1: Process Create |
Rule body
title: Suspicious Child Process of SAP NetWeaver - Linux
id: 69dea60b-2deb-4c9e-a685-ad542f4367f9
status: experimental
description: |
Detects suspicious child processes spawned by SAP NetWeaver on Linux systems that could indicate potential
exploitation of vulnerability that allows arbitrary execution via webshells such as CVE-2025-31324.
author: Elastic (idea), Swachchhanda Shrawan Poudel (Nextron Systems)
date: 2025-04-28
tags:
- attack.execution
- attack.initial-access
- attack.t1190
- attack.persistence
- attack.t1059.003
- cve.2025-31324
- detection.emerging-threats
references:
- https://reliaquest.com/blog/threat-spotlight-reliaquest-uncovers-vulnerability-behind-sap-netweaver-compromise/
- https://onapsis.com/blog/active-exploitation-of-sap-vulnerability-cve-2025-31324/
logsource:
category: process_creation
product: linux
detection:
selection_parent_img:
ParentImage|contains:
- '/j2ee/cluster/apps/sap.com/irj/servlet_jsp/irj/work'
- '/j2ee/cluster/apps/sap.com/irj/servlet_jsp/irj/root'
selection_current_dict:
CurrentDirectory|contains:
- '/j2ee/cluster/apps/sap.com/irj/servlet_jsp/irj/work'
- '/j2ee/cluster/apps/sap.com/irj/servlet_jsp/irj/root'
selection_child:
Image|endswith:
- '/ash'
- '/bash'
- '/csh'
- '/dash'
- '/ksh'
- '/sh'
- '/tcsh'
- '/zsh'
- '/python'
- '/python2'
- '/python3'
- '/perl'
- '/ruby'
- '/curl'
- '/wget'
- '/nc'
- '/netcat'
- '/ncat'
- '/socat'
- '/nmap'
- '/telnet'
- '/awk'
- '/sed'
condition: (selection_parent_img or selection_current_dict) and selection_child
falsepositives:
- Legitimate administrative activities such as software updates
level: medium
Stages and Predicates
Stage 0: condition
(selection_parent_img or selection_current_dict) and selection_childStage 1: selection_parent_img
selection_parent_img:
ParentImage|contains:
- '/j2ee/cluster/apps/sap.com/irj/servlet_jsp/irj/work'
- '/j2ee/cluster/apps/sap.com/irj/servlet_jsp/irj/root'
Stage 2: selection_current_dict
selection_current_dict:
CurrentDirectory|contains:
- '/j2ee/cluster/apps/sap.com/irj/servlet_jsp/irj/work'
- '/j2ee/cluster/apps/sap.com/irj/servlet_jsp/irj/root'
Stage 3: selection_child
selection_child:
Image|endswith:
- '/ash'
- '/bash'
- '/csh'
- '/dash'
- '/ksh'
- '/sh'
- '/tcsh'
- '/zsh'
- '/python'
- '/python2'
- '/python3'
- '/perl'
- '/ruby'
- '/curl'
- '/wget'
- '/nc'
- '/netcat'
- '/ncat'
- '/socat'
- '/nmap'
- '/telnet'
- '/awk'
- '/sed'
Indicators
These rows show field, operator, and value matches.
| Field | Kind | Values | Search |
|---|---|---|---|
CurrentDirectory | match |
| field:"CurrentDirectory" kind:match |
Image | ends_with |
| field:"Image" kind:ends_with |
ParentImage | match |
| field:"ParentImage" kind:match |