Executable or Script file written by a web server process
Synopsis
Field
Value
Activation Period
14 Days
Training Period
30 Days
Test Period
N/A (single event)
Deduplication Period
1 Day
Required Data
XDR Agent with eXtended Threat Hunting (XTH)
Detector Tags
Webshell Analytics
ATT&CK Tactic
Initial Access (TA0001), Persistence (TA0003)
ATT&CK Technique
External Remote Services (T1133), Server Software Component: Web Shell (T1505.003)
Severity
Low
Description
An uncommon executable or script file was created, written, or renamed by a web server process.
Attacker's Goals
Gain the ability to execute commands on the host and establish persistence.
Investigative actions
Review web server access logs for suspicious requests or uploads.
Inspect the dropped file to determine whether it contains malicious content.
Variations
PreviousExecutable moved to Windows system folder
NextExecution of an uncommon process at an early startup stage by Windows system binary
Was this helpful?
