Potential SAP NetWeaver Webshell Creation - Linux — Detection Rule

Detects the creation of suspicious files (jsp, java, class) in SAP NetWeaver directories, which may indicate exploitation attempts of vulnerabilities such as CVE-2025-31324.

Read the full analysis on IntelFusions