- 필수 기능
- 시작하기
- Glossary
- 표준 속성
- Guides
- Agent
- 통합
- 개방형텔레메트리
- 개발자
- Administrator's Guide
- API
- Datadog Mobile App
- CoScreen
- Cloudcraft
- 앱 내
- 서비스 관리
- 인프라스트럭처
- 애플리케이션 성능
- APM
- Continuous Profiler
- 스팬 시각화
- 데이터 스트림 모니터링
- 데이터 작업 모니터링
- 디지털 경험
- 소프트웨어 제공
- 보안
- AI Observability
- 로그 관리
- 관리
Detects a modification to the xp_cmdshell
configuration in Microsoft SQL Server.
This detection monitors Windows event logs for Event ID 15457 from the MSSQLSERVER provider, which indicates configuration changes to the xp_cmdshell
feature. The detection specifically looks for events containing “xp_cmdshell” while excluding changes where the configuration remains disabled (0 to 0) or is being disabled (1 to 0), focusing instead on cases where the feature is being enabled.
The xp_cmdshell
extended stored procedure allows SQL queries to execute operating system commands using the SQL Server service account’s privileges. When enabled, it can be abused by attackers to run arbitrary commands on the host system, potentially leading to privilege escalation, lateral movement, and data exfiltration.
{{host}}
SQL Server instance where the xp_cmdshell
configuration was modified.xp_cmdshell
has legitimate administrative authority over the SQL Server instance.xp_cmdshell
to identify potential malicious activity.xp_cmdshell
immediately if the activity is deemed suspicious or unauthorized.