{"id":"T1505.003","name":"Web Shell","url":"https://attack.mitre.org/techniques/T1505/003","tactics":["persistence"],"platforms":["Linux","macOS","Network Devices","Windows"],"live":true,"revoked":false,"deprecated":false,"revoked_by":null,"detection_strategies":[{"id":"DET0394","stix_id":"x-mitre-detection-strategy--abb052c6-4edd-4592-9b9b-e53a55ac53b8","name":"Web Shell Detection via Server Behavior and File Execution Chains","url":"https://attack.mitre.org/detectionstrategies/DET0394","analytics":[{"id":"AN1108","stix_id":"x-mitre-analytic--66c98f78-2848-43f4-a69d-5562f03712ec","name":"Analytic 1108","description":"Unexpected file creation in web directories followed by web server processes (e.g., w3wp.exe) spawning command shells or script interpreters (e.g., cmd.exe, powershell.exe)","url":"https://attack.mitre.org/detectionstrategies/DET0394#AN1108","platforms":["Windows"],"log_source_references":[{"name":"WinEventLog:Sysmon","channel":"EventCode=11","data_component":"DC0039","data_component_name":"File Creation","log_source_slug":"wineventlog-sysmon"},{"name":"WinEventLog:Sysmon","channel":"EventCode=1","data_component":"DC0032","data_component_name":"Process Creation","log_source_slug":"wineventlog-sysmon"},{"name":"WinEventLog:Security","channel":"EventCode=4624, 4648","data_component":"DC0067","data_component_name":"Logon Session Creation","log_source_slug":"wineventlog-security"},{"name":"NSM:Flow","channel":"Inbound HTTP POST with suspicious payload size or user-agent","data_component":"DC0085","data_component_name":"Network Traffic Content","log_source_slug":"nsm-flow"}],"mutable_elements":[{"field":"WebRootPath","description":"Custom web server directory depending on IIS or third-party hosting environment"},{"field":"ParentProcess","description":"Different server binaries (e.g., php-cgi.exe, apache.exe) that may launch scripts"}],"live":true,"detection_strategies":["DET0394"],"techniques":["T1505.003"]},{"id":"AN1109","stix_id":"x-mitre-analytic--9e80763b-5287-451f-b2ab-37168b159387","name":"Analytic 1109","description":"File creation of unauthorized script (e.g., .php, .sh) in /var/www/html followed by execution of unexpected system utilities (e.g., curl, bash, nc) by apache/nginx","url":"https://attack.mitre.org/detectionstrategies/DET0394#AN1109","platforms":["Linux"],"log_source_references":[{"name":"auditd:SYSCALL","channel":"new file created in /var/www/html, /srv/http, or similar web root","data_component":"DC0039","data_component_name":"File Creation","log_source_slug":"auditd-syscall"},{"name":"auditd:SYSCALL","channel":"apache2 or nginx spawning sh, bash, or python interpreter","data_component":"DC0032","data_component_name":"Process Creation","log_source_slug":"auditd-syscall"},{"name":"NSM:Flow","channel":"POST requests to .php, .jsp, .aspx files with high entropy body","data_component":"DC0085","data_component_name":"Network Traffic Content","log_source_slug":"nsm-flow"}],"mutable_elements":[{"field":"WebRootPath","description":"Web server root varies by distro and hosting configuration"},{"field":"PayloadEntropyThreshold","description":"Base64 or XOR encoded shells may exceed this value"},{"field":"TimeWindow","description":"Correlate file creation with process spawn within X seconds"}],"live":true,"detection_strategies":["DET0394"],"techniques":["T1505.003"]},{"id":"AN1110","stix_id":"x-mitre-analytic--e5a0bbf3-e5d0-41f1-b757-c67eccece77b","name":"Analytic 1110","description":"Web servers (e.g., httpd) spawning abnormal processes post file upload into /Library/WebServer/Documents or /usr/local/var/www","url":"https://attack.mitre.org/detectionstrategies/DET0394#AN1110","platforms":["macOS"],"log_source_references":[{"name":"macos:unifiedlog","channel":"httpd spawning bash, zsh, python, or osascript","data_component":"DC0032","data_component_name":"Process Creation","log_source_slug":"macos-unifiedlog"},{"name":"auditd:SYSCALL","channel":"file write operations in /Library/WebServer/Documents","data_component":"DC0061","data_component_name":"File Modification","log_source_slug":"auditd-syscall"}],"mutable_elements":[{"field":"InterpreterName","description":"Adversary may use different scripting environments"},{"field":"ExecutionParent","description":"Not all web servers are named httpd; may differ in custom deployments"}],"live":true,"detection_strategies":["DET0394"],"techniques":["T1505.003"]}],"live":true,"version":"1.0","techniques":["T1505.003"]}],"sigma_rules":[{"id":"1f0489be-b496-4ddf-b3a9-5900f2044e9c","title":"Suspicious File Write to SharePoint Layouts Directory","author":"Swachchhanda Shrawan Poudel (Nextron Systems)","status":"experimental","level":"high","date":"2025-07-24","modified":null,"description":"Detects suspicious file writes to SharePoint layouts directory which could indicate webshell activity or post-exploitation.\nThis behavior has been observed in the exploitation of SharePoint vulnerabilities such as CVE-2025-49704, CVE-2025-49706 or CVE-2025-53770.\n","references":["https://unit42.paloaltonetworks.com/microsoft-sharepoint-cve-2025-49704-cve-2025-49706-cve-2025-53770/","https://www.microsoft.com/en-us/security/blog/2025/07/22/disrupting-active-exploitation-of-on-premises-sharepoint-vulnerabilities/"],"logsource":{"product":"windows","category":"file_event"},"tags":["attack.initial-access","attack.t1190","attack.persistence","attack.t1505.003"],"path":"rules/windows/file/file_event/file_event_win_susp_filewrite_in_sharepoint_layouts_dir.yml","techniques":["T1190","T1505.003"],"cves":[]},{"id":"2d79e371-2a27-42de-87a4-b4213fc72a6a","title":"Suspicious Process Spawned by CentreStack Portal AppPool","author":"Jason Rathbun (Blackpoint Cyber)","status":"experimental","level":"high","date":"2025-04-17","modified":null,"description":"Detects unexpected command shell execution (cmd.exe) from w3wp.exe when tied to CentreStack's portal.config, indicating potential exploitation (e.g., CVE-2025-30406)\n","references":["https://nvd.nist.gov/vuln/detail/CVE-2025-30406","https://blackpointcyber.com/blog/racing-to-exploit-centrestacks-cve-2025-30406/","https://gladinetsupport.s3.us-east-1.amazonaws.com/gladinet/securityadvisory-cve-2005.pdf","https://www.bleepingcomputer.com/news/security/centrestack-rce-exploited-as-zero-day-to-breach-file-sharing-servers/"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.persistence","attack.execution","attack.t1059.003","attack.t1505.003","cve.2025-30406","detection.emerging-threats"],"path":"rules-emerging-threats/2025/Exploits/CVE-2025-30406/proc_creation_win_exploit_cve_2025_30406_centrestack_portal_child_process.yml","techniques":["T1059.003","T1505.003"],"cves":["CVE-2025-30406"]},{"id":"2ea44a60-cfda-11ea-87d0-0242ac130003","title":"Webshell ReGeorg Detection Via Web Logs","author":"Cian Heasley","status":"test","level":"high","date":"2020-08-04","modified":"2023-01-02","description":"Certain strings in the uri_query field when combined with null referer and null user agent can indicate activity associated with the webshell ReGeorg.","references":["https://community.rsa.com/community/products/netwitness/blog/2019/02/19/web-shells-and-netwitness-part-3","https://github.com/sensepost/reGeorg"],"logsource":{"category":"webserver"},"tags":["attack.persistence","attack.t1505.003"],"path":"rules/web/webserver_generic/web_webshell_regeorg.yml","techniques":["T1505.003"],"cves":[]},{"id":"35efb964-e6a5-47ad-bbcd-19661854018d","title":"Execution From Webserver Root Folder","author":"Florian Roth (Nextron Systems)","status":"test","level":"medium","date":"2019-01-16","modified":"2024-01-18","description":"Detects a program executing from a web server root folder. Use this rule to hunt for potential interesting activity such as webshell or backdoors\n","references":["Internal Research"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.persistence","attack.t1505.003","detection.threat-hunting"],"path":"rules-threat-hunting/windows/process_creation/proc_creation_win_susp_execution_path_webserver.yml","techniques":["T1505.003"],"cves":[]},{"id":"37e8369b-43bb-4bf8-83b6-6dd43bda2000","title":"Oracle WebLogic Exploit","author":"Florian Roth (Nextron Systems)","status":"test","level":"critical","date":"2018-07-22","modified":"2023-01-02","description":"Detects access to a webshell dropped into a keystore folder on the WebLogic server","references":["https://twitter.com/pyn3rd/status/1020620932967223296","https://github.com/LandGrey/CVE-2018-2894"],"logsource":{"category":"webserver"},"tags":["attack.t1190","attack.initial-access","attack.persistence","attack.t1505.003","cve.2018-2894","detection.emerging-threats"],"path":"rules-emerging-threats/2018/Exploits/CVE-2018-2894/web_cve_2018_2894_weblogic_exploit.yml","techniques":["T1190","T1505.003"],"cves":["CVE-2018-2894"]},{"id":"39f1f9f2-9636-45de-98f6-a4046aa8e4b9","title":"Potential Webshell Creation On Static Website","author":"Beyu Denis, oscd.community, Tim Shelton, Thurein Oo","status":"test","level":"medium","date":"2019-10-22","modified":"2023-10-15","description":"Detects the creation of files with certain extensions on a static web site. This can be indicative of potential uploads of a web shell.","references":["PT ESC rule and personal experience","https://github.com/swisskyrepo/PayloadsAllTheThings/blob/c95a0a1a2855dc0cd7f7327614545fe30482a636/Upload%20Insecure%20Files/README.md"],"logsource":{"product":"windows","category":"file_event"},"tags":["attack.persistence","attack.t1505.003"],"path":"rules/windows/file/file_event/file_event_win_webshell_creation_detect.yml","techniques":["T1505.003"],"cves":[]},{"id":"435e41f2-48eb-4c95-8a2b-ed24b50ec30b","title":"MOVEit CVE-2023-34362 Exploitation Attempt - Potential Web Shell Request","author":"Nasreddine Bencherchali (Nextron Systems)","status":"test","level":"high","date":"2023-06-03","modified":"2023-07-28","description":"Detects get requests to specific files used during the exploitation of MOVEit CVE-2023-34362","references":["https://community.progress.com/s/article/MOVEit-Transfer-Critical-Vulnerability-31May2023","https://www.mandiant.com/resources/blog/zero-day-moveit-data-theft"],"logsource":{"category":"webserver"},"tags":["attack.persistence","attack.t1505.003","cve.2023-34362","detection.emerging-threats"],"path":"rules-emerging-threats/2023/Exploits/CVE-2023-34362-MOVEit-Transfer-Exploit/web_cve_2023_34362_known_payload_request.yml.yml","techniques":["T1505.003"],"cves":["CVE-2023-34362"]},{"id":"4ebc877f-4612-45cb-b3a5-8e3834db36c9","title":"Webshell Hacking Activity Patterns","author":"Florian Roth (Nextron Systems)","status":"test","level":"high","date":"2022-03-17","modified":"2023-11-09","description":"Detects certain parent child patterns found in cases in which a web shell is used to perform certain credential dumping or exfiltration activities on a compromised system\n","references":["https://youtu.be/7aemGhaE9ds?t=641"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.persistence","attack.discovery","attack.t1505.003","attack.t1018","attack.t1033","attack.t1087"],"path":"rules/windows/process_creation/proc_creation_win_webshell_hacking.yml","techniques":["T1505.003","T1018","T1033","T1087"],"cves":[]},{"id":"516376b4-05cd-4122-bae0-ad7641c38d48","title":"Mailbox Export to Exchange Webserver","author":"Florian Roth (Nextron Systems), Rich Warren, Christian Burkard (Nextron Systems)","status":"test","level":"critical","date":"2021-08-09","modified":"2023-04-30","description":"Detects a successful export of an Exchange mailbox to untypical directory or with aspx name suffix which can be used to place a webshell or the needed role assignment for it","references":["https://blog.orange.tw/2021/08/proxylogon-a-new-attack-surface-on-ms-exchange-part-1.html"],"logsource":{"product":"windows","service":"msexchange-management"},"tags":["attack.persistence","attack.t1505.003"],"path":"rules/windows/builtin/msexchange/win_exchange_proxyshell_mailbox_export.yml","techniques":["T1505.003"],"cves":[]},{"id":"639b893f-f93a-4e53-a7c8-f08cf73fe7f7","title":"Potential Java WebShell Upload in SAP NetViewer Server","author":"Swachchhanda Shrawan Poudel (Nextron Systems)","status":"experimental","level":"high","date":"2025-05-14","modified":null,"description":"Detects potential Java webshell uploads via HTTP requests with Content-Type 'application/octet-stream' and Java file extensions.\nThis behavior might indicate exploitation of vulnerabilities like CVE-2025-31324, which allows remote code execution through webshells in SAP NetViewer.\n","references":["https://blog.eclecticiq.com/china-nexus-nation-state-actors-exploit-sap-netweaver-cve-2025-31324-to-target-critical-infrastructures"],"logsource":{"category":"webserver"},"tags":["attack.persistence","attack.t1505.003","detection.emerging-threats","cve.2025-31324"],"path":"rules-emerging-threats/2025/Exploits/CVE-2025-31324/web_lnx_exploit_cve_2025_31324_sap_netviewer_webshell_uploaded.yml","techniques":["T1505.003"],"cves":["CVE-2025-31324"]},{"id":"6b269392-9eba-40b5-acb6-55c882b20ba6","title":"Suspicious File Drop by Exchange","author":"Florian Roth (Nextron Systems)","status":"test","level":"medium","date":"2022-10-04","modified":null,"description":"Detects suspicious file type dropped by an Exchange component in IIS","references":["https://www.microsoft.com/security/blog/2022/09/30/analyzing-attacks-using-the-exchange-vulnerabilities-cve-2022-41040-and-cve-2022-41082/","https://www.gteltsc.vn/blog/canh-bao-chien-dich-tan-cong-su-dung-lo-hong-zero-day-tren-microsoft-exchange-server-12714.html","https://en.gteltsc.vn/blog/cap-nhat-nhe-ve-lo-hong-bao-mat-0day-microsoft-exchange-dang-duoc-su-dung-de-tan-cong-cac-to-chuc-tai-viet-nam-9685.html"],"logsource":{"product":"windows","category":"file_event"},"tags":["attack.persistence","attack.t1190","attack.initial-access","attack.t1505.003"],"path":"rules/windows/file/file_event/file_event_win_exchange_webshell_drop_suspicious.yml","techniques":["T1190","T1505.003"],"cves":[]},{"id":"7280c9f3-a5af-45d0-916a-bc01cb4151c9","title":"Suspicious MSExchangeMailboxReplication ASPX Write","author":"Florian Roth (Nextron Systems)","status":"test","level":"high","date":"2022-02-25","modified":null,"description":"Detects suspicious activity in which the MSExchangeMailboxReplication process writes .asp and .apsx files to disk, which could be a sign of ProxyShell exploitation","references":["https://redcanary.com/blog/blackbyte-ransomware/"],"logsource":{"product":"windows","category":"file_event"},"tags":["attack.initial-access","attack.t1190","attack.persistence","attack.t1505.003"],"path":"rules/windows/file/file_event/file_event_win_susp_exchange_aspx_write.yml","techniques":["T1190","T1505.003"],"cves":[]},{"id":"7ff9db12-1b94-4a79-ba68-a2402c5d6729","title":"Windows Webshell Strings","author":"Florian Roth (Nextron Systems), Nasreddine Bencherchali (Nextron Systems)","status":"test","level":"high","date":"2017-02-19","modified":"2022-11-18","description":"Detects common commands used in Windows webshells","references":["https://bad-jubies.github.io/RCE-NOW-WHAT/","https://m365internals.com/2022/10/07/hunting-in-on-premises-exchange-server-logs/"],"logsource":{"category":"webserver"},"tags":["attack.persistence","attack.t1505.003"],"path":"rules/web/webserver_generic/web_win_webshells_in_access_logs.yml","techniques":["T1505.003"],"cves":[]},{"id":"818f7b24-0fba-4c49-a073-8b755573b9c7","title":"Linux Webshell Indicators","author":"Florian Roth (Nextron Systems), Nasreddine Bencherchali (Nextron Systems)","status":"test","level":"high","date":"2021-10-15","modified":"2026-08-19","description":"Detects suspicious sub processes of web server processes","references":["https://www.acunetix.com/blog/articles/web-shells-101-using-php-introduction-web-shells-part-2/","https://media.defense.gov/2020/Jun/09/2002313081/-1/-1/0/CSI-DETECT-AND-PREVENT-WEB-SHELL-MALWARE-20200422.PDF"],"logsource":{"product":"linux","category":"process_creation"},"tags":["attack.persistence","attack.t1505.003"],"path":"rules/linux/process_creation/proc_creation_lnx_webshell_detection.yml","techniques":["T1505.003"],"cves":[]},{"id":"8202070f-edeb-4d31-a010-a26c72ac5600","title":"Suspicious Process By Web Server Process","author":"Thomas Patzke, Florian Roth (Nextron Systems), Zach Stanford @svch0st, Tim Shelton, Nasreddine Bencherchali (Nextron Systems)","status":"test","level":"high","date":"2019-01-16","modified":"2024-11-26","description":"Detects potentially suspicious processes being spawned by a web server process which could be the result of a successfully placed web shell or exploitation\n","references":["https://media.defense.gov/2020/Jun/09/2002313081/-1/-1/0/CSI-DETECT-AND-PREVENT-WEB-SHELL-MALWARE-20200422.PDF"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.persistence","attack.initial-access","attack.t1505.003","attack.t1190"],"path":"rules/windows/process_creation/proc_creation_win_webshell_susp_process_spawned_from_webserver.yml","techniques":["T1505.003","T1190"],"cves":[]},{"id":"869b9ca7-9ea2-4a5a-8325-e80e62f75445","title":"Suspicious Child Process Of SQL Server","author":"FPT.EagleEye Team, wagga","status":"test","level":"high","date":"2020-12-11","modified":"2023-05-04","description":"Detects suspicious child processes of the SQLServer process. This could indicate potential RCE or SQL Injection.","references":["Internal Research"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.t1505.003","attack.t1190","attack.initial-access","attack.persistence","attack.privilege-escalation"],"path":"rules/windows/process_creation/proc_creation_win_mssql_susp_child_process.yml","techniques":["T1505.003","T1190"],"cves":[]},{"id":"89c42960-f244-4dad-9151-ae9b1a3287a2","title":"Suspicious File Write to Webapps Root Directory","author":"Swachchhanda Shrawan Poudel (Nextron Systems)","status":"experimental","level":"medium","date":"2025-10-20","modified":null,"description":"Detects suspicious file writes to the root directory of web applications, particularly Apache web servers or Tomcat servers.\nThis may indicate an attempt to deploy malicious files such as web shells or other unauthorized scripts.\n","references":["https://labs.watchtowr.com/guess-who-would-be-stupid-enough-to-rob-the-same-vault-twice-pre-auth-rce-chains-in-commvault/"],"logsource":{"product":"windows","category":"file_event"},"tags":["attack.persistence","attack.t1505.003","attack.initial-access","attack.t1190"],"path":"rules/windows/file/file_event/file_event_win_susp_file_write_in_webapps_root.yml","techniques":["T1505.003","T1190"],"cves":[]},{"id":"9465ddf4-f9e4-4ebd-8d98-702df3a93239","title":"IIS Native-Code Module Command Line Installation","author":"Florian Roth (Nextron Systems)","status":"test","level":"medium","date":"2019-12-11","modified":"2024-03-13","description":"Detects suspicious IIS native-code module installations via command line","references":["https://researchcenter.paloaltonetworks.com/2018/01/unit42-oilrig-uses-rgdoor-iis-backdoor-targets-middle-east/","https://www.microsoft.com/security/blog/2022/07/26/malicious-iis-extensions-quietly-open-persistent-backdoors-into-servers/"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.persistence","attack.t1505.003"],"path":"rules/windows/process_creation/proc_creation_win_iis_appcmd_susp_module_install.yml","techniques":["T1505.003"],"cves":[]},{"id":"94e12f41-6cb3-45c5-97b1-c783a7bf2e72","title":"Potential SAP NetViewer Webshell Command Execution","author":"Swachchhanda Shrawan Poudel (Nextron Systems)","status":"experimental","level":"high","date":"2025-05-14","modified":null,"description":"Detects potential command execution via webshell in SAP NetViewer through JSP files with cmd parameter.\nThis rule is created to detect exploitation of vulnerabilities like CVE-2025-31324, which allows remote code execution via a webshell.\n","references":["https://blog.eclecticiq.com/china-nexus-nation-state-actors-exploit-sap-netweaver-cve-2025-31324-to-target-critical-infrastructures"],"logsource":{"category":"webserver"},"tags":["attack.persistence","attack.t1505.003","attack.initial-access","attack.t1190","detection.emerging-threats","cve.2025-31324"],"path":"rules-emerging-threats/2025/Exploits/CVE-2025-31324/web_lnx_exploit_cve_2025_31324_sap_netviewer_webshell.yml","techniques":["T1505.003","T1190"],"cves":["CVE-2025-31324"]},{"id":"9db37458-4df2-46a5-95ab-307e7f29e675","title":"Exchange Set OabVirtualDirectory ExternalUrl Property","author":"Jose Rodriguez @Cyb3rPandaH","status":"test","level":"high","date":"2021-03-15","modified":"2023-01-23","description":"Rule to detect an adversary setting OabVirtualDirectory External URL property to a script in Exchange Management log","references":["https://twitter.com/OTR_Community/status/1371053369071132675"],"logsource":{"product":"windows","service":"msexchange-management"},"tags":["attack.persistence","attack.t1505.003"],"path":"rules/windows/builtin/msexchange/win_exchange_set_oabvirtualdirectory_externalurl.yml","techniques":["T1505.003"],"cves":[]},{"id":"9f6a34b4-2688-4eb7-a7f5-e39fef573d0e","title":"Suspicious Windows Strings In URI","author":"Nasreddine Bencherchali (Nextron Systems)","status":"test","level":"high","date":"2022-06-06","modified":"2023-01-02","description":"Detects suspicious Windows strings in URI which could indicate possible exfiltration or webshell communication","references":["https://thedfirreport.com/2022/06/06/will-the-real-msiexec-please-stand-up-exploit-leads-to-data-exfiltration/"],"logsource":{"category":"webserver"},"tags":["attack.persistence","attack.exfiltration","attack.t1505.003"],"path":"rules/web/webserver_generic/web_susp_windows_path_uri.yml","techniques":["T1505.003"],"cves":[]},{"id":"a133193c-2daa-4a29-8022-018695fcf0ae","title":"Rejetto HTTP File Server RCE","author":"Nasreddine Bencherchali (Nextron Systems)","status":"test","level":"high","date":"2022-07-19","modified":"2023-01-02","description":"Detects attempts to exploit a Rejetto HTTP File Server (HFS) via CVE-2014-6287","references":["https://vk9-sec.com/hfs-code-execution-cve-2014-6287/","https://www.exploit-db.com/exploits/39161","https://github.com/Twigonometry/Cybersecurity-Notes/blob/c875b0f52df7d2c7a870e75e1f0c2679d417931d/Writeups/Hack%20the%20Box/Boxes/Optimum/10%20-%20Website.md"],"logsource":{"category":"webserver"},"tags":["attack.persistence","attack.initial-access","attack.t1190","attack.t1505.003","cve.2014-6287","detection.emerging-threats"],"path":"rules-emerging-threats/2014/Exploits/CVE-2014-6287/web_cve_2014_6287_hfs_rce.yml","techniques":["T1190","T1505.003"],"cves":["CVE-2014-6287"]},{"id":"a2cee20b-eacc-459f-861d-c02e5d12f1db","title":"Solarwinds SUPERNOVA Webshell Access","author":"Florian Roth (Nextron Systems)","status":"test","level":"critical","date":"2020-12-17","modified":"2023-01-02","description":"Detects access to SUPERNOVA webshell as described in Guidepoint report","references":["https://www.guidepointsecurity.com/supernova-solarwinds-net-webshell-analysis/","https://www.anquanke.com/post/id/226029"],"logsource":{"category":"webserver"},"tags":["attack.persistence","attack.t1505.003","detection.emerging-threats"],"path":"rules-emerging-threats/2020/TA/SolarWinds-Supply-Chain/web_solarwinds_supernova_webshell.yml","techniques":["T1505.003"],"cves":[]},{"id":"b7bc7038-638b-4ffd-880c-292c692209ef","title":"Certificate Request Export to Exchange Webserver","author":"Max Altgelt (Nextron Systems)","status":"test","level":"critical","date":"2021-08-23","modified":"2023-01-23","description":"Detects a write of an Exchange CSR to an untypical directory or with aspx name suffix which can be used to place a webshell","references":["https://twitter.com/GossiTheDog/status/1429175908905127938"],"logsource":{"product":"windows","service":"msexchange-management"},"tags":["attack.persistence","attack.t1505.003"],"path":"rules/windows/builtin/msexchange/win_exchange_proxyshell_certificate_generation.yml","techniques":["T1505.003"],"cves":[]},{"id":"bd1212e5-78da-431e-95fa-c58e3237a8e6","title":"Suspicious ASPX File Drop by Exchange","author":"Florian Roth (Nextron Systems), MSTI (query, idea)","status":"test","level":"high","date":"2022-10-01","modified":null,"description":"Detects suspicious file type dropped by an Exchange component in IIS into a suspicious folder","references":["https://www.microsoft.com/security/blog/2022/09/30/analyzing-attacks-using-the-exchange-vulnerabilities-cve-2022-41040-and-cve-2022-41082/","https://www.gteltsc.vn/blog/canh-bao-chien-dich-tan-cong-su-dung-lo-hong-zero-day-tren-microsoft-exchange-server-12714.html","https://en.gteltsc.vn/blog/cap-nhat-nhe-ve-lo-hong-bao-mat-0day-microsoft-exchange-dang-duoc-su-dung-de-tan-cong-cac-to-chuc-tai-viet-nam-9685.html"],"logsource":{"product":"windows","category":"file_event"},"tags":["attack.persistence","attack.t1505.003"],"path":"rules/windows/file/file_event/file_event_win_exchange_webshell_drop.yml","techniques":["T1505.003"],"cves":[]},{"id":"bd3b3fff-a018-4994-9876-68af5809160f","title":"Commvault QOperation Path Traversal Webshell Drop (CVE-2025-57790)","author":"Swachchhanda Shrawan Poudel (Nextron Systems)","status":"experimental","level":"high","date":"2025-10-20","modified":null,"description":"Detects the use of qoperation.exe with the -file argument to write a JSP file to the webroot, indicating a webshell drop.\nThis is a post-authentication step corresponding to CVE-2025-57790.\n","references":["https://labs.watchtowr.com/guess-who-would-be-stupid-enough-to-rob-the-same-vault-twice-pre-auth-rce-chains-in-commvault/"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.persistence","attack.t1505.003","detection.emerging-threats","cve.2025-57790"],"path":"rules-emerging-threats/2025/Exploits/CVE-2025-57790/proc_creation_win_exploit_cve_2025_57790.yml","techniques":["T1505.003"],"cves":["CVE-2025-57790"]},{"id":"bed2a484-9348-4143-8a8a-b801c979301c","title":"Webshell Detection With Command Line Keywords","author":"Florian Roth (Nextron Systems), Jonhnathan Ribeiro, Anton Kutepov, oscd.community, Chad Hudson, Matt Anderson","status":"test","level":"high","date":"2017-01-01","modified":"2026-07-14","description":"Detects certain command line parameters often used during reconnaissance activity via web shells","references":["https://www.fireeye.com/blog/threat-research/2013/08/breaking-down-the-china-chopper-web-shell-part-ii.html","https://unit42.paloaltonetworks.com/bumblebee-webshell-xhunt-campaign/","https://www.huntress.com/blog/threat-advisory-oh-no-cleo-cleo-software-actively-being-exploited-in-the-wild"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.persistence","attack.discovery","attack.t1505.003","attack.t1018","attack.t1033","attack.t1087"],"path":"rules/windows/process_creation/proc_creation_win_webshell_recon_commands_and_processes.yml","techniques":["T1505.003","T1018","T1033","T1087"],"cves":[]},{"id":"c0d3734d-330f-4a03-aae2-65dacc6a8222","title":"Webshell Remote Command Execution","author":"Ilyas Ochkov, Beyu Denis, oscd.community","status":"test","level":"critical","date":"2019-10-12","modified":"2025-12-05","description":"Detects possible command execution by web application/web shell","references":["Personal Experience of the Author","https://www.vaadata.com/blog/what-is-command-injection-exploitations-and-security-best-practices/"],"logsource":{"product":"linux","service":"auditd"},"tags":["attack.persistence","attack.t1505.003"],"path":"rules/linux/auditd/syscall/lnx_auditd_web_rce.yml","techniques":["T1505.003"],"cves":[]},{"id":"c67e0c98-4d39-46ee-8f6b-437ebf6b950e","title":"Shellshock Expression","author":"Florian Roth (Nextron Systems)","status":"test","level":"high","date":"2017-03-14","modified":"2022-10-09","description":"Detects shellshock expressions in log files","references":["https://owasp.org/www-pdf-archive/Shellshock_-_Tudor_Enache.pdf"],"logsource":{"product":"linux"},"tags":["attack.persistence","attack.t1505.003"],"path":"rules/linux/builtin/lnx_shellshock.yml","techniques":["T1505.003"],"cves":[]},{"id":"c9e6f412-3d50-4f7e-bf94-5b6c7d8e9f0a","title":"WordPress Wp2shell Webshell Plugin Access","author":"Swachchhanda Shrawan Poudel (Nextron Systems)","status":"experimental","level":"critical","date":"2026-07-19","modified":null,"description":"Detects post-exploitation access to the wp2shell webshell plugin dropped after successful\nexploitation of CVE-2026-63030 and CVE-2026-60137. After the pre-auth SQLi-to-admin bridge is established,\nthe attacker can upload a malicious plugin (wp2shell) to the target WordPress instance.\nAt this phase, the attacker accesses the webshell for command execution and persistence.\n","references":["https://github.com/Icex0/wp2shell-poc","https://slcyber.io/research-center/wp2shell-pre-authentication-rce-in-wordpress-core/","https://wordpress.org/news/2026/07/wordpress-7-0-2-release/"],"logsource":{"category":"webserver"},"tags":["attack.execution","attack.persistence","attack.t1505.003","cve.2026-63030","cve.2026-60137","detection.emerging-threats"],"path":"rules-emerging-threats/2026/Exploits/CVE-2026-63030/web_exploit_cve_2026_63030_webshell_plugin_access.yml","techniques":["T1505.003"],"cves":["CVE-2026-63030","CVE-2026-60137"]},{"id":"f64e5c19-879c-4bae-b471-6d84c8339677","title":"Webshell Tool Reconnaissance Activity","author":"Cian Heasley, Florian Roth (Nextron Systems)","status":"test","level":"high","date":"2020-07-22","modified":"2023-11-09","description":"Detects processes spawned from web servers (PHP, Tomcat, IIS, etc.) that perform reconnaissance looking for the existence of popular scripting tools (perl, python, wget) on the system via the help commands\n","references":["https://ragged-lab.blogspot.com/2020/07/webshells-automating-reconnaissance.html"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.persistence","attack.t1505.003"],"path":"rules/windows/process_creation/proc_creation_win_webshell_tool_recon.yml","techniques":["T1505.003"],"cves":[]},{"id":"fa3c117a-bc0d-416e-a31b-0c0e80653efb","title":"Chopper Webshell Process Pattern","author":"Florian Roth (Nextron Systems), MSTI (query)","status":"test","level":"high","date":"2022-10-01","modified":null,"description":"Detects patterns found in process executions cause by China Chopper like tiny (ASPX) webshells","references":["https://www.microsoft.com/security/blog/2022/09/30/analyzing-attacks-using-the-exchange-vulnerabilities-cve-2022-41040-and-cve-2022-41082/"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.persistence","attack.discovery","attack.t1505.003","attack.t1018","attack.t1033","attack.t1087"],"path":"rules/windows/process_creation/proc_creation_win_webshell_chopper.yml","techniques":["T1505.003","T1018","T1033","T1087"],"cves":[]},{"id":"fcbb4a77-f368-4945-b046-4499a1da69d1","title":"CVE-2021-40539 Zoho ManageEngine ADSelfService Plus Exploit","author":"Sittikorn S, Nuttakorn Tungpoonsup","status":"test","level":"critical","date":"2021-09-10","modified":"2023-01-02","description":"Detects an authentication bypass vulnerability affecting the REST API URLs in ADSelfService Plus (CVE-2021-40539).","references":["https://therecord.media/cisa-warns-of-zoho-server-zero-day-exploited-in-the-wild/","https://www.manageengine.com/products/self-service-password/kb/how-to-fix-authentication-bypass-vulnerability-in-REST-API.html","https://us-cert.cisa.gov/ncas/alerts/aa21-259a"],"logsource":{"category":"webserver"},"tags":["attack.initial-access","attack.t1190","attack.persistence","attack.t1505.003","cve.2021-40539","detection.emerging-threats"],"path":"rules-emerging-threats/2021/Exploits/CVE-2021-40539/web_cve_2021_40539_manageengine_adselfservice_exploit.yml","techniques":["T1190","T1505.003"],"cves":["CVE-2021-40539"]},{"id":"fdf135a2-9241-4f96-a114-bb404948f736","title":"Antivirus - Web Shell Detection Signature","author":"Florian Roth (Nextron Systems), Arnim Rupp","status":"test","level":"high","date":"2018-09-09","modified":"2026-06-29","description":"Detects a highly relevant Antivirus alert that reports a web shell.\nIt's highly recommended to tune this rule to the specific strings used by your anti virus solution by downloading a big WebShell repository from e.g. github and checking the matches.\nThis event must not be ignored just because the AV has blocked the malware but investigate, how it came there in the first place.\n","references":["https://www.nextron-systems.com/?s=antivirus","https://github.com/tennc/webshell","https://www.virustotal.com/gui/file/bd1d52289203866645e556e2766a21d2275877fbafa056a76fe0cf884b7f8819/detection","https://www.virustotal.com/gui/file/308487ed28a3d9abc1fec7ebc812d4b5c07ab025037535421f64c60d3887a3e8/detection","https://www.virustotal.com/gui/file/7d3cb8a8ff28f82b07f382789247329ad2d7782a72dde9867941f13266310c80/detection","https://www.virustotal.com/gui/file/e841675a4b82250c75273ebf0861245f80c6a1c3d5803c2d995d9d3b18d5c4b5/detection","https://www.virustotal.com/gui/file/a80042c61a0372eaa0c2c1e831adf0d13ef09feaf71d1d20b216156269045801/detection","https://www.virustotal.com/gui/file/b219f7d3c26f8bad7e175934cd5eda4ddb5e3983503e94ff07d39c0666821b7e/detection","https://www.virustotal.com/gui/file/b8702acf32fd651af9f809ed42d15135f842788cd98d81a8e1b154ee2a2b76a2/detection","https://www.virustotal.com/gui/file/13ae8bfbc02254b389ab052aba5e1ba169b16a399d9bc4cb7414c4a73cd7dc78/detection"],"logsource":{"category":"antivirus"},"tags":["attack.persistence","attack.t1505.003"],"path":"rules/category/antivirus/av_webshell.yml","techniques":["T1505.003"],"cves":[]},{"id":"fdf96c90-42d5-4406-8a9c-14a2c9a016b5","title":"DEWMODE Webshell Access","author":"Florian Roth (Nextron Systems)","status":"test","level":"high","date":"2021-02-22","modified":"2023-01-02","description":"Detects access to DEWMODE webshell as described in FIREEYE report","references":["https://www.mandiant.com/resources/blog/accellion-fta-exploited-for-data-theft-and-extortion"],"logsource":{"category":"webserver"},"tags":["attack.persistence","attack.t1505.003","detection.emerging-threats"],"path":"rules-emerging-threats/2021/TA/UNC2546/web_unc2546_dewmode_php_webshell.yml","techniques":["T1505.003"],"cves":[]}],"kev_cves":[{"cveID":"CVE-2025-35939","state":"mapped","mapping_types":["primary_impact"]},{"cveID":"CVE-2025-4427","state":"mapped","mapping_types":["secondary_impact"]},{"cveID":"CVE-2025-42999","state":"mapped","mapping_types":["secondary_impact"]},{"cveID":"CVE-2025-31324","state":"mapped","mapping_types":["exploitation_technique"]},{"cveID":"CVE-2025-3928","state":"mapped","mapping_types":["secondary_impact"]},{"cveID":"CVE-2023-20118","state":"mapped","mapping_types":["secondary_impact"]},{"cveID":"CVE-2024-21893","state":"mapped","mapping_types":["secondary_impact"]},{"cveID":"CVE-2023-46805","state":"mapped","mapping_types":["secondary_impact"]},{"cveID":"CVE-2024-21887","state":"mapped","mapping_types":["secondary_impact"]},{"cveID":"CVE-2023-32315","state":"mapped","mapping_types":["primary_impact"]},{"cveID":"CVE-2023-26360","state":"mapped","mapping_types":["secondary_impact"]},{"cveID":"CVE-2023-22952","state":"stale","mapping_types":["secondary_impact"]},{"cveID":"CVE-2022-41082","state":"mapped","mapping_types":["secondary_impact"]},{"cveID":"CVE-2022-22963","state":"mapped","mapping_types":["secondary_impact"]},{"cveID":"CVE-2022-22954","state":"mapped","mapping_types":["primary_impact"]},{"cveID":"CVE-2021-27860","state":"mapped","mapping_types":["primary_impact"]},{"cveID":"CVE-2021-44228","state":"mapped","mapping_types":["secondary_impact"]},{"cveID":"CVE-2021-44077","state":"mapped","mapping_types":["primary_impact"]},{"cveID":"CVE-2020-0688","state":"mapped","mapping_types":["secondary_impact"]},{"cveID":"CVE-2021-26855","state":"mapped","mapping_types":["secondary_impact"]},{"cveID":"CVE-2021-26858","state":"mapped","mapping_types":["primary_impact"]},{"cveID":"CVE-2021-27065","state":"mapped","mapping_types":["primary_impact"]},{"cveID":"CVE-2019-0604","state":"mapped","mapping_types":["primary_impact"]},{"cveID":"CVE-2021-26857","state":"mapped","mapping_types":["primary_impact"]},{"cveID":"CVE-2019-18935","state":"mapped","mapping_types":["primary_impact"]},{"cveID":"CVE-2021-40539","state":"mapped","mapping_types":["primary_impact","secondary_impact"]}],"_built":"2026-08-24 19:45 UTC","_attack_version":"19.2","_sigma_commit":"da9bb07d642a2826e89702445d32c795209ec108"}