Zimbra Swatchdog SNMP Command Injection Execution

Last updated 2 days ago on 2026-09-30
Created 2 days ago on 2026-09-30

About

Detects a Unix shell launched by Perl from a generated Zimbra ".swatchdog_script" when the shell command line contains an "snmptrap" invocation and Zimbra SNMP service fields, followed by an unexpected child process other than "snmptrap". This sequence provides high-confidence evidence of external command execution through CVE-2026-73570, an unauthenticated command-injection vulnerability in Zimbra's SNMP monitoring path.
Tags
Domain: EndpointOS: LinuxUse Case: Threat DetectionUse Case: VulnerabilityTactic: Initial AccessTactic: ExecutionData Source: Elastic DefendThreat: Vulnerability ExploitRule Type: Event Correlation (EQL)Platform: LinuxVuln: CVE-2026-73570Language: eql
Severity
critical
Risk Score
99
MITRE ATT&CK™

Execution (TA0002)(external, opens in a new tab or window)

Initial Access (TA0001)(external, opens in a new tab or window)

False Positive Examples
Authorized security testing or a purpose-built synthetic process fixture may reproduce this lineage. Patched Zimbra 10.1.20 and later invokes `snmptrap` without passing the attacker-controlled value through a shell. On vulnerable installations, legitimate monitoring should launch `snmptrap` from the shell but should not launch another child.
License
Elastic License v2(external, opens in a new tab or window)

Definition

Rule Type
Event Correlation Rule
Integration Pack
Prebuilt Security Detection Rules
Index Patterns
logs-endpoint.events.process-*
Related Integrations

endpoint(external, opens in a new tab or window)

Query
text code block:
sequence by host.id with maxspan=30s [process where host.os.type == "linux" and event.type == "start" and event.action in ("exec", "exec_event", "start") and process.name in ("sh", "bash", "dash", "ash", "zsh", "ksh") and process.parent.name like~ "perl*" and process.parent.command_line like~ "*.swatchdog_script*" and process.command_line like~ "*snmptrap*" and process.command_line like~ "*zmservicename*" and process.command_line like~ "*zmservicestatus*" ] by process.entity_id [process where host.os.type == "linux" and event.type == "start" and event.action in ("exec", "exec_event", "start") and process.name != "snmptrap" ] by process.parent.entity_id

Install detection rules in Elastic Security

Detect Zimbra Swatchdog SNMP Command Injection Execution in the Elastic Security detection engine by installing this rule into your Elastic Stack.

To setup this rule, check out the installation guide for Prebuilt Security Detection Rules(external, opens in a new tab or window).