Zimbra Swatchdog SNMP Command Injection Execution
Detects a Unix shell launched by Perl from a generated Zimbra ".swatchdog_script" when the shell command line contains an "snmptrap" invocation and Zimbra SNMP service fields, followed by an unexpected child process…
Description
Detects a Unix shell launched by Perl from a generated Zimbra ".swatchdog_script" when the shell command line contains an "snmptrap" invocation and Zimbra SNMP service fields, followed by an unexpected child process other than "snmptrap". This sequence provides high-confidence evidence of external command execution through CVE-2026-73570, an unauthenticated command-injection vulnerability in Zimbra's SNMP monitoring path.
Detection logic
Its licence does not clear it for publishing here
Sunturai publishes a detection's own text where the licence it arrived under has been reviewed and permits it, and Elastic License 2.0 has not. The query as its source wrote it, its canonical form and the hash that pins this revision are in the workspace record.
Detection requirements
- Platform
- ContainersESXiIaaSIdentity ProviderLinuxmacOSNetwork DevicesOffice SuiteSaaSWindows
The rule states no platform. This is derived from the 2 ATT&CK techniques it maps to.
- Log source category
- event_index
Known benign triggers
- Authorized security testing or a purpose-built synthetic process fixture may reproduce this lineage. Patched Zimbra 10.1.20 and later invokes `snmptrap` without passing the attacker-controlled value through a shell. On vulnerable installations, legitimate monitoring should launch `snmptrap` from the shell but should not launch another child.
MITRE ATT&CK mappings
0 exclusive techniques.This is coverage no other published rule has; it is not this rule's total technique count.
References
| Reference | Cited by |
|---|---|
| wiki.zimbra.com/wiki/Zimbra_Releases/10.1.20 | Only this detection cites it |
| wiki.zimbra.com/wiki/Zimbra_Security_Advisories | Only this detection cites it |
| www.cisa.gov/known-exploited-vulnerabilities-catalog?search=CVE-2026-73570 | Only this detection cites it |
| www.microsoft.com/en-us/security/blog/2026/09/30/unauthenticated-command-injection-on-internet-facing-mail-servers-tracking-cve-2026-73570/ | Only this detection cites it |
| www.pruva.dev/reproductions/REPRO-2026-00327 | Only this detection cites it |
From the source
- At source
- Open at source
- Upstream identifier
- 1fa1a434-75a7-4c58-9bef-331d62bf3f82
- Tagged by the source as
- Data Source: Elastic DefendDomain: EndpointOS: LinuxPlatform: LinuxResources: Investigation GuideRule Type: Event Correlation (EQL)Tactic: ExecutionTactic: Initial AccessThreat: Vulnerability ExploitUse Case: Threat DetectionUse Case: VulnerabilityVuln: CVE-2026-73570
Licence
- Published under
- Elastic License 2.0Read the licence
- Attribution
- Required
Authorship
- Written by
- Published
- Oct 2, 2026
- Version
- 1