Article Banner

ShinyHunters Renews Mass Exploitation of Oracle PeopleSoft Through a WAF Bypass

A criminal group known as ShinyHunters has restarted a worldwide hacking campaign against Oracle PeopleSoft, the software many large organizations use to run human resources, payroll, and student records. Earlier this year the group broke into universities through a hidden flaw. It has now found a simple trick to slip past the web filters companies installed to block that flaw, and it is striking targets across many industries.

The trick works like changing one letter in a banned word so an automated filter no longer recognizes it, even though the door it guards still opens. The request looks slightly different, so the filter waves it through while the attack lands exactly as before. Teams that believed the filter closed the door may still be wide open.

Once inside, the group plants hidden tools, steals the passwords stored on the server, and quietly copies out sensitive employee and customer data. ShinyHunters is known for demanding payment and threatening to publish what it takes. For any organization still running the unpatched software, one exposed server can lead to stolen payroll and HR records, long-term hidden access, and public extortion.

Hunting Controls & Observations

Mandiant and the Google Threat Intelligence Group (GTIG) attribute this activity to UNC6240, the actor publicly known as ShinyHunters. After weaponizing CVE-2026-35273 as a zero-day against universities in June 2026, the actor modified its exploit to defeat the web application firewall (WAF) rules organizations had deployed over the vulnerable PeopleSoft Environment Management Hub (PSEMHUB) endpoint. The exploit sends a Java deserialization payload to the hub servlet using a percent-encoded request path (/%50SEMHUB/ in place of /PSEMHUB/), so any WAF or proxy rule that matches the literal path before decoding fails to block it. Because PSEMHUB runs inside the WebLogic application server and roughly a quarter of the actor's commands execute as root or NT Authority\SYSTEM, the strongest detection opportunities live in the web-tier access logs, in endpoint process and file telemetry on the PeopleSoft hosts, and in the egress and database records that reveal credential theft and data staging. Organizations can detect this activity through multiple telemetry sources:

  • Network Controls: PeopleSoft Internet Architecture (PIA) WebLogic access logs for requests to /PSEMHUB/ and any percent-encoded or mixed-case variant, POST requests to /hub from external source addresses, and requests to unexpected .jsp or .jspx files under PSEMHUB or PORTAL; NetFlow and firewall egress for connections to the campaign's command-and-control hosts and Microsoft-masquerading domains; and DNS logs for those domains
  • Endpoint Controls: EDR/XDR, Windows Sysmon, and Linux auditd or Sysmon-for-Linux process-creation telemetry (shell processes spawned by the WebLogic Java process), file integrity monitoring on the PSEMHUB.war and PORTAL.war web directories, and detection of archive files written to /tmp or web-accessible paths
  • Identity & Access Controls: access to and reuse of credentials readable from the web tier, including database connection strings in psappsrv.cfg, Integration Broker credentials, and cloud credentials
  • Database & Application Controls: database audit logs for bulk queries or exports against HR, payroll, and student-records tables

Behavioral Indicators of Attack

The following behaviors, drawn from the Mandiant and GTIG analysis, are more durable than any single indicator because the actor rotates infrastructure, varies file hashes, and reuses legitimate remote-management tooling:

  • A burst of five to fifteen external POST requests to the Environment Management Hub endpoint using a percent-encoded path such as /%50SEMHUB/hub rather than the literal /PSEMHUB/, the signature of WAF-bypass exploitation and target verification.
  • The WebLogic Java process spawning a command shell (cmd.exe on Windows, /bin/sh or bash on Linux), especially one that decodes an encoded payload, opens an outbound network connection, or enumerates the host.
  • New .jsp or .jspx files appearing in the PSEMHUB.war or PORTAL.war directory that are not part of the shipped product, often with short generic names such as x.jsp, u.jsp, or tunnel.jsp.
  • Command output returned directly in the HTTP response to the hub endpoint with no file written to disk, the fileless execution path that leaves no web shell behind.
  • Base64-encoded file content uploaded in roughly 150 KB chunks and reassembled on disk, a technique that bypasses HTTP request-size limits and native file-chunking handlers.
  • An unexpected Windows executable dropped into the web directory, launched as a background process, and then confirmed with a tasklist query, the delivery pattern for the SIDEEYE backdoor.
  • A SOCKS proxy tunnel established through the web server (Neo-reGeorg), enabling internal discovery and lateral movement outward from the PeopleSoft host.
  • Remote-management agents dropped to /tmp that beacon to Microsoft-masquerading domains, and large .tar, .tar.gz, or .zst archives staged before sustained outbound transfers over rsync, SSH, or HTTP POST.

MITRE Enterprise ATT&CK Tactics and Techniques

Mandiant and GTIG map this campaign across the kill chain from reconnaissance through exfiltration:

Controls' Observables

Network Controls

Because the Environment Management Hub is an administrative, system-to-system component, external access to it is abnormal and web-tier logs carry the highest-value signals.

  • Encoded hub exploitation: POST requests to /%50SEMHUB/hub or any other percent-encoded or mixed-case variant of the path from external source addresses.
    • Related MITRE Techniques: T1190, T1027
    • Detection Difficulty: LOW
  • Web shell retrieval: Requests to unexpected .jsp or .jspx files under PSEMHUB or PORTAL, often carrying a hex-encoded command parameter.
    • Related MITRE Techniques: T1505.003
    • Detection Difficulty: LOW
  • Egress to known infrastructure: Connections from a PeopleSoft host to the campaign's controller and exfiltration IPs or to the Microsoft-masquerading domains used for remote management.
    • Related MITRE Techniques: T1219, T1090, T1048
    • Detection Difficulty: LOW
  • Bulk and tunneled transfers: Sustained outbound rsync (TCP/873), SSH, or HTTP POST traffic and SOCKS5 proxy patterns originating from the web tier.
    • Related MITRE Techniques: T1048, T1090
    • Detection Difficulty: MEDIUM

Endpoint Controls

On the PeopleSoft hosts themselves, process and file telemetry capture the execution and persistence stages that follow exploitation.

  • Web server spawning shells: The WebLogic Java process launching cmd.exe, /bin/sh, or bash, especially when the child process decodes a payload, opens an outbound connection, or runs host-enumeration commands.
    • Related MITRE Techniques: T1059.003, T1059.004
    • Detection Difficulty: MEDIUM
  • Web-root file writes: New .jsp, .jspx, or .exe files created in PSEMHUB.war or PORTAL.war, including under envmetadata/transactions/.
    • Related MITRE Techniques: T1505.003
    • Detection Difficulty: MEDIUM
  • Unexpected remote-management agent: MeshAgent binaries and configuration files (meshagent, meshagent.msh, meshagent.db) dropped to /tmp under the PeopleSoft service account.
    • Related MITRE Techniques: T1219
    • Detection Difficulty: MEDIUM
  • Archive staging: Large .tar, .tar.gz, or .zst files in /tmp or web-accessible directories, and tar, zstd, rsync, sshpass, or curl processes spawned by the web-tier service account.
    • Related MITRE Techniques: T1048
    • Detection Difficulty: MEDIUM

Identity & Access Controls

The actor harvests every credential reachable from the compromised web tier, so credential-file access and anomalous reuse are key signals.

  • Credential-file access: Reads of psappsrv.cfg database connection strings, Integration Broker credentials, and cloud credentials from the web tier.
    • Related MITRE Techniques: T1552.001
    • Detection Difficulty: HIGH
  • Privileged web-tier execution: Commands running as root or NT Authority\SYSTEM from the WebLogic process, which should rarely occur during normal operation.
    • Related MITRE Techniques: T1059.003, T1059.004
    • Detection Difficulty: MEDIUM

Database & Application Controls

Application-layer telemetry ties the compromise to concrete data theft.

  • Bulk record access: Large or sustained queries and exports against HR, payroll, and student-records tables outside normal reporting patterns.
    • Related MITRE Techniques: T1048
    • Detection Difficulty: HIGH

Insights and Recommendation

Organizations that fall victim face full operating-system control of an internet-facing PeopleSoft server, theft of every credential stored on or reachable from it, and a staging point for deeper intrusion. The actor layers persistence through JSP web shells, the SIDEEYE backdoor delivered by a trojanized installer, and legitimate MeshAgent remote-management software, while a Neo-reGeorg SOCKS tunnel opens the internal network to discovery and lateral movement. Because UNC6240 follows a well-established pattern of data-theft extortion, a compromise typically ends in stolen HR, payroll, and student records and a demand for payment under threat of public release on a data-leak site.

As of 2026-10-02, AlienVault OTX catalogs this campaign's indicators across more than a dozen public threat-intelligence pulses that cite the Mandiant and GTIG report, linking them to the SIDEEYE, Neo-reGeorg, and MeshAgent families and to the UNC6240 actor. AbuseIPDB shows the controller and exfiltration hosts carrying near-zero abuse reputation on clean commercial hosting as of the same date, for example 5.199.162.157 at 1% confidence on Cherry Servers in Lithuania and 104.219.234.138 at 0% on DataWagon in the United States (ASN AS27176, per AlienVault OTX). Reputation feeds alone will not flag this infrastructure, which is exactly why behavioral detection outperforms indicator matching for this activity.

Security teams should apply the Oracle Security Alert patch for CVE-2026-35273 immediately and treat WAF rules and path-based blocking as a stopgap rather than a fix, since a single encoded character defeats them. Disable the Environment Management Hub in multi-server configurations or remove the PSEMHUB application entirely in single-server configurations, and restrict EMHub and the Integration Broker listening connector from public internet access, which is non-breaking for standard PIA user sessions. Hunt the PIA WebLogic access logs for /PSEMHUB/ and every percent-encoded variant and for external POST requests to /hub (T1190, T1027), and alert on the WebLogic process spawning shells or writing new files into the web root (T1059, T1505.003). Inspect the PSEMHUB.war directory for files that are not part of the shipped product, rotate every credential reachable from the PeopleSoft service account including the psappsrv.cfg connection strings, Integration Broker, and cloud credentials (T1552.001), and monitor outbound traffic to the listed infrastructure and for unexpected MeshCentral agents (T1219). Treat any discovered web shell as a full host compromise, preserve evidence, and prepare for extortion contact.

Source and Credits

This summary is based on Mandiant and the Google Threat Intelligence Group's research article "ShinyHunters Renewed Mass Exploitation Campaign Targeting Oracle PeopleSoft" published on September 25, 2026.

Live-status corroboration for selected indicators was provided by Darknet CTI corroboration (Focused Hunts), drawing on AlienVault OTX and AbuseIPDB as checked on 2026-10-02. This is a secondary source used only to confirm current infrastructure reputation and public cataloging; all threat behavior and attribution derive from the Mandiant and GTIG report.

Threat Hunting IOCs & Queries

The actor varies file hashes, rotates infrastructure, and reuses legitimate tooling, so treat the indicators below as seeds and rely on the behavioral queries for durable detection. The authoritative indicator set is published by Mandiant and GTIG in a Google Threat Intelligence collection on VirusTotal (collection ID 23dd0be8f55d6ab7e425806a1a02847a8898bdfe0b7e9c1745e558240147532b).

Known Indicators of Compromise

  • File Hashes (SHA256):
    • 48b4a0827da7bbfce9fb52464f8a659dea7a035189c52c506c0bfb4b1c3fe494 – x.jsp primary command-execution web shell (hash varies due to newline characters)
    • 2bee941fb40519d0d1ec52bd79a8f63fc65aac6455c8f2d6b668e3360dfdb5d7 – u.jsp chunked file-upload and execution stager
    • 419c571ee38b7e7266d130c4b6bbc4dd0ef44d6e5f3bc02cc2cf73b762f07c86 – tunnel.jsp Neo-reGeorg JSP tunnel (hash varies by key)
    • ba14419beb2ec0bb94cab6298c14d7fb3e1d819366fe378290c0c2a4d97f7e07 – tunnel.jspx Neo-reGeorg JSPX tunnel (hash varies by key)
    • 3ba215692665513abfffd4e815c5c45f2d41e5dcc4283a2a3b740930c5c417c3 – Ple64.exe trojanized Light Alloy installer delivering the SIDEEYE backdoor (AlienVault OTX: cataloged across 14 public pulses tied to this campaign, as of 2026-10-02)
  • Domains:
    • winmanage-me.network – MeshCentral infrastructure; resolves to 104.219.234.138 (AlienVault OTX: cataloged across 12 public pulses tied to this campaign, as of 2026-10-02)
    • azurenetfiles.net – Microsoft-masquerading domain for MeshAgent command and control
    • microsoft-entra.net – Microsoft-masquerading domain for MeshAgent command and control
    • enroll.azuredevice.cloud – Microsoft-masquerading domain for MeshAgent command and control
  • IP Addresses:
    • 5.199.162.157 – attack controller, scanner, and HTTP callback receiver (AbuseIPDB 1% confidence, 1 report, UAB Cherry Servers data-center hosting in Lithuania, last reported 2026-09-26, as of 2026-10-02)
    • 104.219.234.138 – exfiltration staging and remote-management host (AbuseIPDB 0% confidence, 0 reports, DataWagon LLC data-center hosting in the United States; ASN AS27176 DataWagon LLC per AlienVault OTX, as of 2026-10-02)
    • 162.219.30.165 – SIDEEYE backdoor command and control (TCP/3333 control, TCP/3334 data) (AbuseIPDB 0% confidence, 0 reports, DataWagon LLC data-center hosting in the United Kingdom, as of 2026-10-02)
  • File Paths:
    • <PS_CFG_HOME>/webserv/<domain>/applications/peoplesoft/PSEMHUB.war/ – drop location for x.jsp, u.jsp, u2.jsp, tunnel.jsp, tunnel.jspx, and Ple64.exe
    • .../PSEMHUB.war/envmetadata/transactions/ – directory inspected for unauthorized content
    • /tmp/meshagent, /tmp/meshagent.msh, /tmp/meshagent.db – MeshAgent binary and configuration on Linux
  • URI Patterns: /%50SEMHUB/ and /%50SEMHUB/hub (percent-encoded WAF-bypass path; assume any percent-encoded, mixed-case, or non-normalized variant of /PSEMHUB/)
  • Code-Signing Certificate: subject "Tobias Weihmann Software Development OU", issued by Sectigo (Extended Validation); GTIG requested revocation

Notes: Indicators are current as of the Mandiant and GTIG report (September 25, 2026). Live-status annotations reflect AlienVault OTX and AbuseIPDB corroboration on 2026-10-02, a secondary source distinct from the cited report; per-IP ASN and ownership are from AlienVault OTX, while hosting usage type and abuse confidence are from AbuseIPDB. The controller and exfiltration IPs carry near-zero abuse reputation on clean commercial hosting, which underscores why behavioral detection outperforms reputation matching for this activity.

Encoded PSEMHUB Exploitation and Hub POST Bursts

Behavior Targeted: Detects external access to the Environment Management Hub using percent-encoded or mixed-case path variants and bursts of POST requests to the hub endpoint, the WAF-bypass exploitation and target-verification signature.
MITRE ATT&CK: T1190, T1027
Expected Results: External source addresses sending encoded /%50SEMHUB/ requests or repeated POST requests to the hub endpoint; the Environment Management Hub should only be reached by internal system-to-system agents on the literal path.
False Positive Likelihood: LOW
Tuning Guidance: Requires PeopleSoft web, WAF, or proxy access logs mapped to the CIM Web data model in Splunk, or forwarded to Sentinel as Syslog; any percent-encoded variant from an external source is suspicious, and the literal path from an external source is itself abnormal. Internal EMHub agents use the literal /PSEMHUB/ path.

Splunk SPL Query

| tstats summariesonly=false count min(_time) AS first_seen max(_time) AS last_seen
    from datamodel=Web.Web
    where earliest=-45d Web.url="*SEMHUB*"
    by Web.src Web.http_method Web.url
| rename Web.* AS *
| eval path_encoded=if(match(url,"(?i)%[0-9a-f]{2}"),"yes","no")
| eval hub_post=if(http_method="POST" AND match(url,"(?i)SEMHUB/hub"),"yes","no")
| where path_encoded="yes" OR hub_post="yes"
| stats sum(count) AS count dc(url) AS distinct_uris values(url) AS uris
    min(first_seen) AS first_seen max(last_seen) AS last_seen by src
| where count >= 5 OR distinct_uris > 1
| sort - count
| convert ctime(first_seen) ctime(last_seen)

Microsoft KQL Query (Defender/Sentinel)

Syslog
| where TimeGenerated > ago(45d)
| where SyslogMessage has "SEMHUB"
| extend PathEncoded = iif(SyslogMessage matches regex @"(?i)%[0-9A-Fa-f]{2}.*SEMHUB" or SyslogMessage has "%50SEMHUB", "yes", "no")
| extend HubPost = iif(SyslogMessage has "POST" and SyslogMessage has "SEMHUB/hub", "yes", "no")
| where PathEncoded == "yes" or HubPost == "yes"
| summarize Count = count(), Samples = make_set(SyslogMessage, 10), FirstSeen = min(TimeGenerated), LastSeen = max(TimeGenerated) by HostName
| order by Count desc

Note: These queries were generated with AI assistance. Test thoroughly in your environment before production use.

WebLogic Java Process Spawning Command Shells

Behavior Targeted: Detects the PeopleSoft WebLogic Java process spawning an interactive command shell, the execution stage that follows both web-shell and fileless exploitation.
MITRE ATT&CK: T1059.003, T1059.004
Expected Results: A Java parent process launching cmd.exe, /bin/sh, or bash, especially when the child process decodes a payload, opens an outbound connection, or runs host-enumeration commands.
False Positive Likelihood: LOW
Tuning Guidance: Requires Sysmon (Event 1) on Windows and auditd or Sysmon for Linux on the PeopleSoft hosts (mapped to the CIM Endpoint data model in Splunk); a WebLogic application server should rarely spawn an interactive shell, so treat any hit as high priority.

Splunk SPL Query

| tstats summariesonly=false count min(_time) AS first_seen max(_time) AS last_seen
    values(Processes.process) AS cmds
    from datamodel=Endpoint.Processes
    where earliest=-45d
        Processes.parent_process_name IN ("java","java.exe","javaw.exe")
        Processes.process_name IN ("cmd.exe","sh","bash")
    by Processes.dest Processes.user Processes.parent_process_name Processes.process_name
| rename Processes.* AS *
| sort - count
| convert ctime(first_seen) ctime(last_seen)

Microsoft KQL Query (Defender/Sentinel)

DeviceProcessEvents
| where Timestamp > ago(45d)
| where InitiatingProcessFileName has "java"
| where FileName in~ ("cmd.exe","sh","bash")
| project Timestamp, DeviceName, AccountName, InitiatingProcessFileName, FileName, ProcessCommandLine
| order by Timestamp desc

Note: These queries were generated with AI assistance. Test thoroughly in your environment before production use.

Unexpected Web Shell and Executable Writes to the PeopleSoft Web Directory

Behavior Targeted: Detects new JSP, JSPX, or executable files written into the PeopleSoft web application directories, the persistence stage where web shells and the trojanized installer land.
MITRE ATT&CK: T1505.003
Expected Results: Creation of .jsp, .jspx, or .exe files in PSEMHUB.war or PORTAL.war that are not part of a vendor patch, often with short generic names.
False Positive Likelihood: MEDIUM
Tuning Guidance: The shipped product is a known baseline, so any new file in these directories is suspect; add envmetadata/transactions/ to the path list, watch for short names such as x.jsp, u.jsp, tunnel.jsp, and Ple64.exe, correlate with change windows, and flag writes whose parent is the WebLogic Java process.

Splunk SPL Query

| tstats summariesonly=false count min(_time) AS first_seen max(_time) AS last_seen
    values(Filesystem.file_path) AS files
    from datamodel=Endpoint.Filesystem
    where earliest=-45d
        (Filesystem.file_path="*PSEMHUB.war*" OR Filesystem.file_path="*PORTAL.war*")
        Filesystem.file_name IN ("*.jsp","*.jspx","*.exe")
    by Filesystem.dest Filesystem.user Filesystem.action
| rename Filesystem.* AS *
| sort - first_seen
| convert ctime(first_seen) ctime(last_seen)

Microsoft KQL Query (Defender/Sentinel)

DeviceFileEvents
| where Timestamp > ago(45d)
| where FolderPath has_any ("PSEMHUB.war","PORTAL.war")
| where FileName endswith ".jsp" or FileName endswith ".jspx" or FileName endswith ".exe"
| where ActionType in ("FileCreated","FileModified")
| project Timestamp, DeviceName, InitiatingProcessFileName, InitiatingProcessAccountName, FolderPath, FileName, ActionType
| order by Timestamp desc

Note: These queries were generated with AI assistance. Test thoroughly in your environment before production use.

Outbound C2, Masquerading Domains, and Remote-Management Beacons

Behavior Targeted: Detects a PeopleSoft host connecting to the campaign's known controller and exfiltration IPs or to the Microsoft-masquerading domains used by MeshAgent, an estate-wide sweep to scope the intrusion.
MITRE ATT&CK: T1219, T1090, T1048
Expected Results: Connections or DNS resolutions from the web tier to the published indicators, including raw TCP to the SIDEEYE control and data ports.
False Positive Likelihood: LOW
Tuning Guidance: Seed the lists from the Mandiant and GTIG post and extend them from the Google Threat Intelligence collection as infrastructure rotates; stronger still, baseline your PeopleSoft hosts and alert on any outbound session they initiate to external hosting IP space, including a MeshCentral agent or raw TCP on 3333/3334 (the SIDEEYE control and data ports).

Splunk SPL Query

| tstats summariesonly=false count min(_time) AS first_seen max(_time) AS last_seen
    from datamodel=Network_Traffic.All_Traffic
    where earliest=-60d
        All_Traffic.dest_ip IN ("5.199.162.157","104.219.234.138","162.219.30.165")
    by All_Traffic.src_ip All_Traffic.dest_ip All_Traffic.dest_port
| rename All_Traffic.* AS *
| eval indicator=dest_ip
| append
    [| tstats summariesonly=false count min(_time) AS first_seen max(_time) AS last_seen
        from datamodel=Network_Resolution.DNS
        where earliest=-60d
            DNS.query IN ("*azurenetfiles.net","*microsoft-entra.net","enroll.azuredevice.cloud","*winmanage-me.network")
        by DNS.src DNS.query
    | rename DNS.src AS src_ip, DNS.query AS indicator]
| stats sum(count) AS count values(indicator) AS indicators values(dest_port) AS ports
    min(first_seen) AS first_seen max(last_seen) AS last_seen by src_ip
| sort - count
| convert ctime(first_seen) ctime(last_seen)

Microsoft KQL Query (Defender/Sentinel)

DeviceNetworkEvents
| where Timestamp > ago(60d)
| where RemoteIP in ("5.199.162.157","104.219.234.138","162.219.30.165")
    or RemoteUrl has_any ("azurenetfiles.net","microsoft-entra.net","enroll.azuredevice.cloud","winmanage-me.network")
| project Timestamp, DeviceName, InitiatingProcessFileName, RemoteIP, RemoteUrl, RemotePort, InitiatingProcessCommandLine
| order by Timestamp desc

Note: These queries were generated with AI assistance. Test thoroughly in your environment before production use.

Data Staging and Bulk Exfiltration From the PeopleSoft Tier

Behavior Targeted: Detects archive creation and compression or transfer utilities run by the PeopleSoft or WebLogic service accounts, the data-theft stage that precedes extortion.
MITRE ATT&CK: T1048
Expected Results: tar, zstd, rsync, sshpass, or curl processes spawned by the web-tier service account, and large archive files written to /tmp or web-accessible directories.
False Positive Likelihood: MEDIUM
Tuning Guidance: Set the service-account list to your PeopleSoft and WebLogic run-as accounts and baseline scheduled backup jobs; pair with firewall logs for rsync (TCP/873), SSH, and large HTTP POST egress from the same host.

Splunk SPL Query

| tstats summariesonly=false count min(_time) AS first_seen max(_time) AS last_seen
    values(Processes.process) AS cmds
    from datamodel=Endpoint.Processes
    where earliest=-60d
        (Processes.process_name IN ("tar","zstd","rsync","sshpass","curl","tar.exe","curl.exe")
            OR Processes.process IN ("*.tar.zst*","*.tar.gz*"))
    by Processes.dest Processes.user Processes.parent_process_name Processes.process_name
| rename Processes.* AS *
| where match(user,"(?i)psadm|weblogic|peoplesoft|oracle") OR match(parent_process_name,"(?i)java")
| sort - count
| convert ctime(first_seen) ctime(last_seen)

Microsoft KQL Query (Defender/Sentinel)

DeviceProcessEvents
| where Timestamp > ago(60d)
| where FileName in~ ("tar","zstd","rsync","sshpass","curl","tar.exe","curl.exe")
    or ProcessCommandLine has_any (".tar.zst",".tar.gz",".tar ")
| where InitiatingProcessAccountName has_any ("psadm","weblogic","peoplesoft","oracle")
    or InitiatingProcessFileName has "java"
| project Timestamp, DeviceName, InitiatingProcessAccountName, FileName, ProcessCommandLine, FolderPath
| order by Timestamp desc

Note: These queries were generated with AI assistance. Test thoroughly in your environment before production use.

Back to Hunting off the Red