LoFP LoFP / t1505.003

t1505.003

TitleTags
admin activity
baseline your environment before production. it is possible build systems using iis will spawn cmd.exe to perform a software build. filter as needed.
crazy web applications
false positives are present when the values are set to 1 for utf and lookup. it's possible to raise this to ttp (direct notable) if removal of other_lookups occur and score is raised to 2 (down from 4).
legitimate administrator or developer creating legitimate executable files in a web application folder
legitimate application and websites that use windows paths in their url
legitimate os functions called by vendor applications, baseline the environment and filter before enabling. recommend throttle by dest/process_name
particular web applications may spawn a shell process legitimately
the jsp file names are static names used in current proof of concept code. =
the query is structured in a way that `action` (read, create) is not defined. review the results of this query, filter, and tune as necessary. it may be necessary to generate this query specific to your endpoint product.
there might be false positives associted with this detection since items like args as a web argument is pretty generic.
unknown as it may vary from organisation to organisation how admins use to install iis modules
unlikely
user searches in search boxes of the respective website
web applications that invoke linux command line tools
web applications that use the same url parameters as regeorg
web sites like wikis with articles on os commands and pages that include the os commands in the urls