SIDEEYE backdoor (Ple64.exe) deployed via PeopleSoft/WebLogic web shell
Detects the execution of the SIDEEYE backdoor (Ple64.exe) when it is spawned by web-based processes such as Java (WebLogic) or shell interpreters (cmd.exe/powershell.exe) invoked by web-based parents. This behavior is indicative of a web shell exploitation attempt.
Microsoft Sentinel (KQL)

