• CommunityEnterprisePlans
  • Intel Exchange
    Intel ExchangeDetections
  • Resources
  • About
  • Leaderboard
Join CommunitySign In
    All Detections

    Ivanti EPMM Web Shell Creation

    avatar
    GlassDiceBearhttps://www.dicebear.comhttps://creativecommons.org/publicdomain/zero/1.0/„Glass” (https://www.dicebear.com) by „DiceBear”, licensed under „CC0 1.0” (https://creativecommons.org/publicdomain/zero/1.0/)
    Ethan Andrews@eandrews
    •updated Feb 19, 2026•2•0•73

    This rule detects the creation of specific JSP web shell filenames (1.jsp, 401.jsp, 403.jsp) and suspicious CSS files in the Ivanti EPMM web application directory. This activity is indicative of post-exploitation persistence following the exploitation of vulnerabilities like CVE-2026-1281 or CVE-2026-1340.

    Microsoft Sentinel (KQL)

    Tags

    T1505.003 - Web ShellT1105 - Ingress Tool TransferS1117 - GLASSTOKENC0029 - Cutting EdgeTA0003 - PersistenceTA0011 - Command and ControlFile CreationLinuxGeneric Application LogCVE-2026-1340CVE-2026-1281kql

    Found in

    • Coruna iOS Exploit Kit and Web ExploitationLast updated 3 days ago
    • Coruna iOS Exploit Kit and Web ExploitationLast updated 3 days ago
    • Coruna iOS Exploit Kit and Web ExploitationLast updated 3 days ago
    • Coruna iOS Exploit Kit and Web ExploitationLast updated 3 days ago
    • Coruna iOS Exploit Kit and Web ExploitationLast updated 3 days ago
    • MuddyWater Adopts Russian CastleRAT Malware-as-a-ServiceLast updated Apr 9, 2026

    Community Inspired.
    AI Enhanced.
    Better Detections.

    Follow Us

    Company

    • About
    • Leaderboard

    Product

    • Community
    • Enterprise
    • Plans

    © 2026 Copyright. All Rights Reserved.

    Privacy PolicyTerms of Service

    Sign up to view this detection

    or

    Already have an account?