mirror of
https://github.com/splunk/security_content
synced 2026-06-08 17:32:49 +00:00
11c909f725
* Add YAML formatting and validation infrastructure - Add yamlfmt configuration (.yamlfmt) with 4-space indent, LF line endings - Add yamllint configuration (.yamllint) for syntax validation (detections/ only) - Add pre-commit hook for automatic YAML formatting - Add CI validation script with unified error output - Add GitHub Actions workflow for PR validation - Add documentation for setup and usage - Support custom yamlfmt binary path via --yamlfmt-path flag * comment yaml check from pre-commit * apply yamlfmt * Update yaml-validation.yml * Update yaml-validation.yml * application folder search formatting * cloud folder search formatting * web folder search formatting * network folder search formatting * endpoint folder search formatting * resolve first conflict * apply formatting * remove additional pipe * Update README.md * update versions * restore and update formatting (#3920) --------- Co-authored-by: Bhavin Patel <bhavin.j.patel91@gmail.com>
42 lines
2.1 KiB
YAML
42 lines
2.1 KiB
YAML
name: Suspicious Java Classes
|
|
id: 6ed33786-5e87-4f55-b62c-cb5f1168b831
|
|
version: 6
|
|
date: '2026-02-25'
|
|
author: Jose Hernandez, Splunk
|
|
status: experimental
|
|
type: Anomaly
|
|
description: The following analytic identifies suspicious Java classes often used for remote command execution exploits in Java frameworks like Apache Struts. It detects this activity by analyzing HTTP POST requests with specific content patterns using Splunk's `stream_http` data source. This behavior is significant because it may indicate an attempt to exploit vulnerabilities in web applications, potentially leading to unauthorized remote code execution. If confirmed malicious, this activity could allow attackers to execute arbitrary commands on the server, leading to data breaches, system compromise, and further network infiltration.
|
|
data_source: []
|
|
search: |-
|
|
`stream_http` http_method=POST http_content_length>1
|
|
| regex form_data="(?i)java\.lang\.(?:runtime
|
|
| processbuilder)"
|
|
| rename src_ip as src
|
|
| stats count earliest(_time) as firstTime, latest(_time) as lastTime, values(url) as uri, values(status) as status, values(http_user_agent) as http_user_agent
|
|
BY src, dest
|
|
| `security_content_ctime(firstTime)`
|
|
| `security_content_ctime(lastTime)`
|
|
| `suspicious_java_classes_filter`
|
|
how_to_implement: In order to properly run this search, Splunk needs to ingest data from your web-traffic appliances that serve or sit in the path of your Struts application servers. This can be accomplished by indexing data from a web proxy, or by using network traffic-analysis tools, such as Splunk Stream or Bro.
|
|
known_false_positives: There are no known false positives.
|
|
references: []
|
|
rba:
|
|
message: Suspicious Java Classes in HTTP requests involving $src$ and $dest$
|
|
risk_objects:
|
|
- field: src
|
|
type: system
|
|
score: 25
|
|
- field: dest
|
|
type: system
|
|
score: 25
|
|
threat_objects: []
|
|
tags:
|
|
analytic_story:
|
|
- Apache Struts Vulnerability
|
|
asset_type: Endpoint
|
|
product:
|
|
- Splunk Enterprise
|
|
- Splunk Enterprise Security
|
|
- Splunk Cloud
|
|
security_domain: threat
|