SUPERNOVA webshell

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · 📊

Back to Content Index


Identifies SUPERNOVA webshell based on W3CIISLog data. References: - https://unit42.paloaltonetworks.com/solarstorm-supernova/

Attribute Value
Type Analytic Rule
Solution Web Shells Threat Protection
ID 2acc91c3-17c2-4388-938e-4eac2d5894e8
Severity High
Kind Scheduled
Tactics Persistence, CommandAndControl
Techniques T1505, T1071
Required Connectors AzureMonitor(IIS)
Source View on GitHub

Tables Used

This content item queries data from the following tables:

Table Transformations Ingestion API Lake-Only
W3CIISLog ?

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · 📊

Back to Analytic Rules · Back to Web Shells Threat Protection