# How to write a kibana rule with filename

**URL:** <https://discuss.elastic.co/t/how-to-write-a-kibana-rule-with-filename/272673>\
**Category:** SIEM\
**Created:** [May 11, 2021, 10:24am UTC](https://discuss.elastic.co/t/how-to-write-a-kibana-rule-with-filename/272673 "2021-05-11T10:24:54Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![realtech2338](https://avatars.discourse-cdn.com/v4/letter/r/76d3ee/32.png) [@realtech2338](https://discuss.elastic.co/u/realtech2338)\
**Post date:** [May 11, 2021, 10:24am UTC](https://discuss.elastic.co/t/how-to-write-a-kibana-rule-with-filename/272673/1 "2021-05-11T10:24:55Z")

</div>

I would like to write a rule to detect if the file name & path are matching for china chopper webshells from below list. for entire csv

> <https://gist.github.com/JohnHammond/0b4a45cad4f4ed3324939d72dc599883#file-china_chopper_webshells-csv>

What is the best way to do please guide me with exact steps. I know we need create new rule under detections but i need exact steps like query filename or filepath et......

---

<div class="post-metadata">

**Author:** ![austinsonger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/austinsonger/32/78994_2.png) [@austinsonger](https://discuss.elastic.co/u/austinsonger)\
**Post date:** [May 12, 2021, 1:14am UTC](https://discuss.elastic.co/t/how-to-write-a-kibana-rule-with-filename/272673/2 "2021-05-12T01:14:05Z")

</div>

If this is in relation to the recent use of it with Hafnium’s back in March. Then you can use a rule that was already created,

- [detection-rules/initial\_access\_suspicious\_ms\_exchange\_files.toml at 6ef5c53b0c15e344f0f2d1649941391aea6fa253 · elastic/detection-rules (github.com)](https://github.com/elastic/detection-rules/blob/6ef5c53b0c15e344f0f2d1649941391aea6fa253/rules/windows/initial_access_suspicious_ms_exchange_files.toml)

Or you can use

This one directly reference China Chopper

[sigma/win\_webshell\_detection.yml at master · SigmaHQ/sigma (github.com)](https://github.com/SigmaHQ/sigma/blob/master/rules/windows/process_creation/win_webshell_detection.yml)

```auto
((process.parent.executable:(*\\\\w3wp.exe OR *\\\\php\\-cgi.exe OR 
*\\\\nginx.exe OR *\\\\httpd.exe) OR process.parent.executable:(*\\\\apache* OR 
*\\\\tomcat*)) AND (((process.command_line:(*\\ user\\ * OR *\\ use\\ * OR 
*\\ group\\ *) AND process.executable:(*\\\\net.exe OR *\\\\net1.exe)) OR 
(process.command_line:*\\ \\-n\\ * AND process.executable:*\\\\ping.exe) OR 
process.command_line:(*&cd&echo* OR *cd\\ \\/d\\ *)) OR 
(process.command_line:*\\ \\/node\\:* AND process.executable:*\\\\wmic.exe) OR 
process.executable:(*\\\\whoami.exe OR *\\\\systeminfo.exe OR *\\\\quser.exe OR 
*\\\\ipconfig.exe OR *\\\\pathping.exe OR *\\\\tracert.exe OR *\\\\netstat.exe OR 
*\\\\schtasks.exe OR *\\\\vssadmin.exe OR *\\\\wevtutil.exe OR 
*\\\\tasklist.exe) OR process.command_line:(*\\ Test\\-NetConnection\\ * OR 
*dir\\ \\\\*)))

```

> I just made it into a gist. [ChinaChopper.ndjson (github.com)](https://gist.github.com/austinsonger/599cd62ff93097ea88338ace3efef2d0)

[Florian Roth on Twitter: "It may be hard to detect #Webshells in your Sandbox 🙃 But there's a generic way to detect webshells w/ Sigma rules that trigger on susp parent-\>child process relations @FireEye example China Chopper https://t.co/uPakffpbOv Rules https://t.co/Wet38TQIrv https://t.co/7c2nlFeVhV https://t.co/HdqeWZQjLa" / Twitter](https://twitter.com/cyb3rops/status/1187992532023676929?lang=en)

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 9, 2021, 1:15am UTC](https://discuss.elastic.co/t/how-to-write-a-kibana-rule-with-filename/272673/3 "2021-06-09T01:15:03Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
