Cross-source coverage
T1100 / ATT&CK
Web Shell
ATT&CK has retired this technique. Rules still tag it; the current id is T1505.003 Server Software Component: Web Shell.
7 rules across 1 source.
Showing deprecated rules · back to the default
From MITRE ATT&CK 19.2
A Web shell is a Web script that is placed on an openly accessible Web server to allow an adversary to use the Web server as a gateway into a network. A Web shell may provide a set of functions to execute or a command-line interface on the system that hosts the Web server. In addition to a server-side script, a Web shell may have a client interface program that is used to talk to the Web server (see, for example, China Chopper Web shell client).
Web shells may serve as Redundant Access or as a persistence mechanism in case an adversary's primary access methods are detected and removed.
- Tactics
- Persistence · Privilege Escalation
- Platforms
- Linux · Windows · macOS
- Telemetry
- —
chronicle/detection-rules
7 rules| Detection | Severity | Format |
|---|---|---|
| antivirus_web_shell_detection | Undefined | YARA-L |
| atlassian_confluence_download_attachments_remote_code_executiondirectory_traversal | Undefined | YARA-L |
| oracle_weblogic_exploit | Undefined | YARA-L |
| shells_spawned_by_web_servers | Undefined | YARA-L |
| turla_backdoor_sysmon | Undefined | YARA-L |
| webshell_detection_with_command_line_keywords | Undefined | YARA-L |
| webshell_detection_with_sysmon_logs | Undefined | YARA-L |