Possible webshell file written by a web server process
Synopsis
Field
Value
Activation Period
14 Days
Training Period
30 Days
Test Period
N/A (single event)
Deduplication Period
1 Day
Required Data
XDR Agent with eXtended Threat Hunting (XTH)
Detector Tags
Webshell Analytics
ATT&CK Tactic
Initial Access (TA0001), Persistence (TA0003)
ATT&CK Technique
External Remote Services (T1133), Server Software Component: Web Shell (T1505.003)
Severity
Low
Description
An uncommon file with a web file extension was created, written or renamed by a web server process.
Attacker's Goals
Gaining the ability to execute commands on the host, as well as persistence.
Investigative actions
Investigate the web server access logs for suspicious behavior.
Check if the dropped file contains malicious content.
Variations
Was this helpful?
