Uncommon jsp file write by a Java process
Synopsis
Field
Value
Activation Period
14 Days
Training Period
30 Days
Test Period
N/A (single event)
Deduplication Period
1 Day
Required Data
XDR Agent with eXtended Threat Hunting (XTH)
ATT&CK Tactic
Persistence (TA0003)
ATT&CK Technique
Server Software Component: Web Shell (T1505.003)
Severity
Medium
Description
An uncommon jsp file was written by a Java process.
Attacker's Goals
Persistence on the host.
Investigative actions
Check if the file was added during regular java process actions.
Check if the jsp file contains malicious content.
Was this helpful?
