1200KM / detection
T1505.004 IIS Components — Detection Rules
Detection workspace for T1505.004 IIS Components: 5 Sigma sources, 0 Atlas concepts and 0 anomaly models. No live detection validation.
Source-backed rule directory
- ETW Logging/Processing Option Disabled On IIS Server · test · medium · {"product":"windows","service":"iis-configuration"}
- HTTP Logging Disabled On IIS Server · test · high · {"product":"windows","service":"iis-configuration"}
- New Module Module Added To IIS Server · test · medium · {"product":"windows","service":"iis-configuration"}
- Previously Installed IIS Module Was Removed · test · low · {"product":"windows","service":"iis-configuration"}
- Suspicious IIS Module Registration · test · high · {"category":"process_creation","product":"windows"}
Atlas deterministic concepts
No exact concept selected.
Anomaly models
No exact Atlas model in this snapshot.
ATT&CK analytic guidance
DET0068 Detection Strategy for T1505.004 - Malicious IIS Components
AN0184 Analytic 0184
Adversary installs or modifies IIS components (ISAPI filters, extensions, or modules) using DLL files registered via configuration changes or administrative tools like AppCmd.exe. These components intercept or manipulate HTTP requests/responses for persistence or C2.
Connected ecosystem references
Linked tags
Simulation, tools and telemetry
T1505.004 simulation workspace
- Application Log Content · DC0038
- File Creation · DC0039
- File Modification · DC0061
- Module Load · DC0016
- Process Creation · DC0032
- Service Modification · DC0065
No reviewed association in this snapshot.
Existing anomaly research
Pinned research references. No browser attack runner, live simulation result or validated detector is asserted. Source mappings and validation limits are preserved. ATT&CK / Atomic provenance · Detection provenance.