LoFP LoFP / authorized security testing or a purpose-built synthetic process fixture may reproduce this lineage. patched zimbra 10.1.20 and later invokes `snmptrap` without passing the attacker-controlled value through a shell. on vulnerable installations, legitimate monitoring should launch `snmptrap` from the shell but should not launch another child.

Techniques

Sample rules

Zimbra Swatchdog SNMP Command Injection Execution

Description

Detects a Unix shell launched by Perl from a generated Zimbra “.swatchdog_script” when the shell command line contains an “snmptrap” invocation and Zimbra SNMP service fields, followed by an unexpected child process other than “snmptrap”. This sequence provides high-confidence evidence of external command execution through CVE-2026-73570, an unauthenticated command-injection vulnerability in Zimbra’s SNMP monitoring path.

Detection logic

sequence by host.id with maxspan=30s
  [process where
    host.os.type == "linux" and
    event.type == "start" and
    event.action in ("exec", "exec_event", "start") and
    process.name in ("sh", "bash", "dash", "ash", "zsh", "ksh") and
    process.parent.name like~ "perl*" and
    process.parent.command_line like~ "*.swatchdog_script*" and
    process.command_line like~ "*snmptrap*" and
    process.command_line like~ "*zmservicename*" and
    process.command_line like~ "*zmservicestatus*"
  ] by process.entity_id
  [process where
    host.os.type == "linux" and
    event.type == "start" and
    event.action in ("exec", "exec_event", "start") and
    process.name != "snmptrap"
  ] by process.parent.entity_id