Skip to content

Conversation

@swachchhanda000
Copy link
Collaborator

Summary of the Pull Request

SAP Netweaver CVE-2025-31324 Potential Exploitation

Changelog

new: Potential SAP NetWeaver Webshell Creation - Linux
new: Potential SAP NetWeaver Webshell Creation
new: Suspicious Child Process of SAP NetWeaver - Linux
new: Suspicious Child Process of SAP NetWeaver

Example Log Event

Fixed Issues

SigmaHQ Rule Creation Conventions

  • If your PR adds new rules, please consider following and applying these conventions

@frack113
Copy link
Member

Why not use /j2ee/cluster/apps/sap.com/irj/servlet_jsp/irj/ for the path ?

@swachchhanda000
Copy link
Collaborator Author

Why not use /j2ee/cluster/apps/sap.com/irj/servlet_jsp/irj/ for the path ?

Done

Copy link
Member

@frack113 frack113 left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM

@phantinuss phantinuss requested a review from Copilot October 1, 2025 10:00
Copy link
Contributor

Copilot AI left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull Request Overview

This PR adds detection rules for potential exploitation of SAP NetWeaver CVE-2025-31324, focusing on identifying webshell creation and suspicious child processes that could indicate compromise.

  • Adds detection rules for suspicious child processes spawned by SAP NetWeaver on both Windows and Linux
  • Implements file event monitoring for potential webshell creation in SAP NetWeaver directories
  • Targets CVE-2025-31324 exploitation attempts through process and file monitoring

Reviewed Changes

Copilot reviewed 4 out of 4 changed files in this pull request and generated 4 comments.

File Description
proc_creation_win_sap_netweaver_susp_child_process.yml Windows process creation rule detecting suspicious child processes from SAP NetWeaver
proc_creation_lnx_sap_nwtweaver_sup_child_process.yml Linux process creation rule detecting suspicious child processes from SAP NetWeaver
file_event_win_sap_netweaver_webshell_creation.yml Windows file event rule detecting potential webshell creation in SAP NetWeaver directories
file_event_lnx_sap_netweaver_webshell_creation.yml Linux file event rule detecting potential webshell creation in SAP NetWeaver directories

Tip: Customize your code reviews with copilot-instructions.md. Create the file or learn how to get started.

Copy link
Contributor

Copilot AI left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull Request Overview

Copilot reviewed 4 out of 4 changed files in this pull request and generated 2 comments.


Tip: Customize your code reviews with copilot-instructions.md. Create the file or learn how to get started.

@phantinuss phantinuss merged commit aecbc15 into SigmaHQ:master Oct 1, 2025
12 checks passed
@phantinuss phantinuss added this to the Sigma-August-Release milestone Oct 1, 2025
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants