Salt Typhoon Exchange Web Shell, DLL Sideload, and w3wp Shell Spawn
This rule monitors for suspicious activity related to Microsoft Exchange server exploitation and persistence techniques. It detects three distinct behaviors: the creation of web shell files (.aspx, .ashx, .asmx) within Exchange directories (OWA/ECP), the spawning of shell processes (cmd, powershell) by the w3wp.exe web server process, and DLL sideloading occurring through identified signed binaries (dfsvc.exe, rasautou.exe) outside of standard system directories.
Microsoft Sentinel (KQL)

