1200kmSECURITY RESEARCH

1200KM / sigma-rule

Potential RCE Exploitation Attempt In NodeJS — Sigma Rule

Sigma rule 97661d9d-2beb-4630-b423-68985291a8af. Potential RCE Exploitation Attempt In NodeJS — Sigma Rule. Detects process execution related errors in NodeJS. If the exceptions are caused due to user input then they may suggest an RCE vulnerability.

Rule metadata and linked tags

Author: Moti Harmats. Source status: test; severity: high. Source dates: 2023-02-11 / not supplied.

{
  "category": "application",
  "product": "nodejs",
  "definition": "Requirements: application error logs must be collected (with LOG_LEVEL=ERROR and above)"
}

Pinned original Sigma rule · Detection Rule License 1.1

Source SHA-256: 09d125f6f6faf300235fca870e326ff882a4ff924150e90460abbbdf3c091281

Detection logic

Original source YAML. Source-tag agreement is not proof of complete semantic coverage. This rule has not been compiled for a SIEM backend or validated against live telemetry here.

title: Potential RCE Exploitation Attempt In NodeJS
id: 97661d9d-2beb-4630-b423-68985291a8af
status: test
description: Detects process execution related errors in NodeJS. If the exceptions are caused due to user input then they may suggest an RCE vulnerability.
references:
    - https://www.wix.engineering/post/threat-and-vulnerability-hunting-with-application-server-error-logs
author: Moti Harmats
date: 2023-02-11
tags:
    - attack.initial-access
    - attack.t1190
logsource:
    category: application
    product: nodejs
    definition: 'Requirements: application error logs must be collected (with LOG_LEVEL=ERROR and above)'
detection:
    keywords:
        - 'node:child_process'
    condition: keywords
falsepositives:
    - Puppeteer invocation exceptions often contain child_process related errors, that doesn't necessarily mean that the app is vulnerable.
level: high

Original YAML and metadata in JSON

False positives

  • Puppeteer invocation exceptions often contain child_process related errors, that doesn't necessarily mean that the app is vulnerable.

Source references

Connected ecosystem references

Exact source-tagged techniques

Telemetry review

Read the original logsource above, then inspect the linked detection workspaces for technique-level sensor context. No per-rule telemetry equivalence is inferred.

Pinned research references. No browser attack runner, live simulation result or validated detector is asserted. Source mappings and validation limits are preserved. ATT&CK / Atomic provenance · Detection provenance.