heroui logo

Zimbra Swatchdog SNMP Command Injection Execution

Elastic Detection Rules

View Source
Summary
Detects a Unix shell launched by Perl from a generated Zimbra .swatchdog_script when the shell command line contains an snmptrap invocation and Zimbra SNMP service fields, followed by an unexpected child process other than snmptrap. The sequence indicates external command execution due to CVE-2026-73570 in Zimbra's SNMP monitoring path. The rule relies on Linux process-start events to correlate a Perl parent spawning a shell (sh, bash, dash, etc.) whose parent command line includes the generated .swatchdog_script, with the shell’s command line containing snmptrap and Zimbra service fields, and a second child process (not snmptrap) created by that shell. This yields high-confidence evidence of command injection even if payloads are encoded, altered, or not written to disk. The detection maps to MITRE ATT&CK techniques T1059.004 (Unix Shell) under Execution and T1190 (Exploit Public-Facing Application) under Initial Access. False positives may arise from legitimate testing or synthetic fixtures; ensure patch coverage for Zimbra (10.1.20+) and constrain exceptions to specific hosts/timeframes. The rule should be complemented with off-host log and network telemetry to identify the remote source and text forged in logs. Triage involves preserving the process tree, identifying the unexpected child, extracting the injected command, and correlating with forged service-status text in Zimbra logs; remediation includes isolating the host, upgrading Zimbra, rotating credentials, removing persistence mechanisms, and rebuilding compromised systems as needed.
Categories
  • Endpoint
  • Linux
Data Sources
  • Process
  • Command
ATT&CK Techniques
  • T1059
  • T1059.004
  • T1190
Created: 2026-09-30