1200KM / detection
T1505 Server Software Component — Detection Rules
Detection workspace for T1505 Server Software Component: 1 Sigma sources, 0 Atlas concepts and 0 anomaly models. No live detection validation.
Source-backed rule directory
- Cisco Modify Configuration · test · medium · {"product":"cisco","service":"aaa"}
Atlas deterministic concepts
No exact concept selected.
Anomaly models
No exact Atlas model in this snapshot.
ATT&CK analytic guidance
DET0547 Detection Strategy for T1505 - Server Software Component
AN1507 Analytic 1507
Installation of malicious IIS/Apache/SQL server modules that later execute command-line interpreters or establish outbound connections.
AN1508 Analytic 1508
Abuse of extensible server modules (e.g., Apache, Nginx, Tomcat) to load rogue plugins that initiate bash, connect to C2, or spawn reverse shells.
AN1509 Analytic 1509
Malicious use of webserver plugins (e.g., for nginx, PHP, Node.js) that execute AppleScript or open network sockets.
AN1510 Analytic 1510
Use of ESXi web interface plugins or vSphere extensions to embed persistent malicious scripts or services.
Connected ecosystem references
Linked tags
Simulation, tools and telemetry
- Application Log Content · DC0038
- Command Execution · DC0064
- Network Traffic Content · DC0085
- Network Traffic Flow · DC0078
- Process Creation · DC0032
- Scheduled Job Creation · DC0001
No reviewed association in this snapshot.
Existing anomaly research
Pinned research references. No browser attack runner, live simulation result or validated detector is asserted. Source mappings and validation limits are preserved. ATT&CK / Atomic provenance · Detection provenance.