Ivanti EPMM Web Shell Creation
This rule detects the creation of specific JSP web shell filenames (1.jsp, 401.jsp, 403.jsp) and suspicious CSS files in the Ivanti EPMM web application directory. This activity is indicative of post-exploitation persistence following the exploitation of vulnerabilities like CVE-2026-1281 or CVE-2026-1340.
Microsoft Sentinel (KQL)

