Techniques
Sample rules
Zimbra Swatchdog SNMP Command Injection Execution
- source: elastic
- technicques:
- T1059
- T1190
Description
Detects a Unix shell launched by Perl from a generated Zimbra “.swatchdog_script” when the shell command line contains an “snmptrap” invocation and Zimbra SNMP service fields, followed by an unexpected child process other than “snmptrap”. This sequence provides high-confidence evidence of external command execution through CVE-2026-73570, an unauthenticated command-injection vulnerability in Zimbra’s SNMP monitoring path.
Detection logic
sequence by host.id with maxspan=30s
[process where
host.os.type == "linux" and
event.type == "start" and
event.action in ("exec", "exec_event", "start") and
process.name in ("sh", "bash", "dash", "ash", "zsh", "ksh") and
process.parent.name like~ "perl*" and
process.parent.command_line like~ "*.swatchdog_script*" and
process.command_line like~ "*snmptrap*" and
process.command_line like~ "*zmservicename*" and
process.command_line like~ "*zmservicestatus*"
] by process.entity_id
[process where
host.os.type == "linux" and
event.type == "start" and
event.action in ("exec", "exec_event", "start") and
process.name != "snmptrap"
] by process.parent.entity_id