Web server CGO executed an uncommon process
Synopsis
Field
Value
Activation Period
14 Days
Training Period
30 Days
Test Period
N/A (single event)
Deduplication Period
1 Day
Required Data
XDR Agent
Detector Tags
Webshell Analytics
ATT&CK Tactic
Initial Access (TA0001), Persistence (TA0003)
ATT&CK Technique
External Remote Services (T1133), Server Software Component: Web Shell (T1505.003)
Severity
Informational
Description
An uncommon process was executed by a web server CGO, which might indicate a Webshell activity or a web server exploit.
Attacker's Goals
Gaining the ability to execute commands on the host, as well as persistence.
Investigative actions
Investigate the web server access logs for suspicious behavior.
Check if the executed process is malicious or executes a suspicious action.
Variations
PreviousWeb server CGO executed a process following a potential Webshell dropped
NextWebDAV drive mounted from net.exe over HTTPS
Was this helpful?
