Web server CGO executed a process following a potential Webshell dropped
Synopsis
Field
Value
Activation Period
14 Days
Training Period
30 Days
Test Period
4 Hours
Deduplication Period
1 Day
Required Data
XDR Agent with eXtended Threat Hunting (XTH)
Detector Tags
Webshell Analytics
ATT&CK Tactic
Persistence (TA0003)
ATT&CK Technique
Server Software Component: Web Shell (T1505.003)
Severity
Informational
Description
A process was executed by a web server CGO following a potential drop of a webshell file.
Attacker's Goals
Gaining the ability to execute commands on the host, as well as persistence.
Investigative actions
Investigate the web server access logs for suspicious behavior.
Check if the dropped file contains malicious content.
Was this helpful?
