1200kmSECURITY RESEARCH
Loading interactive filters…

1200KM / detection

T1505 Server Software Component — Detection Rules

Detection workspace for T1505 Server Software Component: 1 Sigma sources, 0 Atlas concepts and 0 anomaly models. No live detection validation.

Source-backed rule directory

Atlas deterministic concepts

No exact concept selected.

Anomaly models

No exact Atlas model in this snapshot.

ATT&CK analytic guidance

DET0547 Detection Strategy for T1505 - Server Software Component

AN1507 Analytic 1507

Installation of malicious IIS/Apache/SQL server modules that later execute command-line interpreters or establish outbound connections.

AN1508 Analytic 1508

Abuse of extensible server modules (e.g., Apache, Nginx, Tomcat) to load rogue plugins that initiate bash, connect to C2, or spawn reverse shells.

AN1509 Analytic 1509

Malicious use of webserver plugins (e.g., for nginx, PHP, Node.js) that execute AppleScript or open network sockets.

AN1510 Analytic 1510

Use of ESXi web interface plugins or vSphere extensions to embed persistent malicious scripts or services.

Connected ecosystem references

Linked tags

Simulation, tools and telemetry

T1505 simulation workspace

No reviewed association in this snapshot.

Existing anomaly research

Original publication snapshot · Anomaly Detection Atlas

Pinned research references. No browser attack runner, live simulation result or validated detector is asserted. Source mappings and validation limits are preserved. ATT&CK / Atomic provenance · Detection provenance.