1200KM / detection
T1505.003 Web Shell — Detection Rules
Detection workspace for T1505.003 Web Shell: 23 Sigma sources, 1 Atlas concepts and 0 anomaly models. No live detection validation.
Source-backed rule directory
- Antivirus Web Shell Detection · test · high · {"category":"antivirus"}
- Webshell Remote Command Execution · test · critical · {"product":"linux","service":"auditd","definition":"Required auditd configuration:\n-a always,exit -F arch=b32 -S execve -F euid=33 -k detect_execve_www\n-a always,exit -F arch=b64 -S execve -F euid=33 -k detect_execve_www\n-a always,exit -F arch=b32 -S execveat -F euid=33 -k detect_execve_www\n-a always,exit -F arch=b64 -S execveat -F euid=33 -k detect_execve_www\nChange the number \"33\" to the ID of your WebServer user. Default: www-data:x:33:33\n"}
- Shellshock Expression · test · high · {"product":"linux"}
- Linux Webshell Indicators · test · high · {"product":"linux","category":"process_creation"}
- Suspicious Windows Strings In URI · test · high · {"category":"webserver"}
- Webshell ReGeorg Detection Via Web Logs · test · high · {"category":"webserver"}
- Windows Webshell Strings · test · high · {"category":"webserver"}
- Certificate Request Export to Exchange Webserver · test · critical · {"service":"msexchange-management","product":"windows"}
- Mailbox Export to Exchange Webserver · test · critical · {"service":"msexchange-management","product":"windows"}
- Exchange Set OabVirtualDirectory ExternalUrl Property · test · high · {"product":"windows","service":"msexchange-management"}
- Suspicious ASPX File Drop by Exchange · test · high · {"product":"windows","category":"file_event"}
- Suspicious File Drop by Exchange · test · medium · {"product":"windows","category":"file_event"}
- Suspicious MSExchangeMailboxReplication ASPX Write · test · high · {"product":"windows","category":"file_event"}
- Suspicious File Write to Webapps Root Directory · experimental · medium · {"product":"windows","category":"file_event"}
- Suspicious File Write to SharePoint Layouts Directory · experimental · high · {"product":"windows","category":"file_event"}
- Potential Webshell Creation On Static Website · test · medium · {"product":"windows","category":"file_event"}
- IIS Native-Code Module Command Line Installation · test · medium · {"category":"process_creation","product":"windows"}
- Suspicious Child Process Of SQL Server · test · high · {"category":"process_creation","product":"windows"}
- Chopper Webshell Process Pattern · test · high · {"category":"process_creation","product":"windows"}
- Webshell Hacking Activity Patterns · test · high · {"category":"process_creation","product":"windows"}
- Webshell Detection With Command Line Keywords · test · high · {"category":"process_creation","product":"windows"}
- Suspicious Process By Web Server Process · test · high · {"category":"process_creation","product":"windows"}
- Webshell Tool Reconnaissance Activity · test · high · {"category":"process_creation","product":"windows"}
Atlas deterministic concepts
T1505.003 Web Shell
MATCH(new_or_modified_file IN web_root) AND extension IN executable_server_extensions -> ALERT; SEQUENCE(web_request, web_server_child_process) WITHIN 1m -> ALERTAnomaly models
No exact Atlas model in this snapshot.
ATT&CK analytic guidance
DET0394 Web Shell Detection via Server Behavior and File Execution Chains
AN1108 Analytic 1108
Unexpected file creation in web directories followed by web server processes (e.g., w3wp.exe) spawning command shells or script interpreters (e.g., cmd.exe, powershell.exe)
AN1109 Analytic 1109
File creation of unauthorized script (e.g., .php, .sh) in /var/www/html followed by execution of unexpected system utilities (e.g., curl, bash, nc) by apache/nginx
AN1110 Analytic 1110
Web servers (e.g., httpd) spawning abnormal processes post file upload into /Library/WebServer/Documents or /usr/local/var/www
Connected ecosystem references
Linked tags
Simulation, tools and telemetry
T1505.003 simulation workspace
- File Creation · DC0039
- File Modification · DC0061
- Logon Session Creation · DC0067
- Network Traffic Content · DC0085
- Process Creation · DC0032
No reviewed association in this snapshot.
Threat actor context
These are explicit actor-to-technique associations in the existing Threat Matrix snapshot, not attribution of an event or proof that a detector identifies the actor. No tool-to-actor relationship is inferred.
- APT28 · G0007
- Deep Panda · G0009
- APT29 · G0016
- Threat Group-3390 · G0027
- Sandworm Team · G0034
- Dragonfly · G0035
- OilRig · G0049
- APT32 · G0050
- Magic Hound · G0059
- Leviathan · G0065
- Tropic Trooper · G0081
- APT38 · G0082
- APT39 · G0087
- GALLIUM · G0093
- Kimsuky · G0094
- Fox Kitten · G0117
- Volatile Cedar · G0123
- HAFNIUM · G0125
- Mustang Panda · G0129
- Tonto Team · G0131
- BackdoorDiplomacy · G0135
- Ember Bear · G1003
- Moses Staff · G1009
- CURIUM · G1012
- FIN13 · G1016
- Volt Typhoon · G1017
- APT5 · G1023
- Agrius · G1030
- Sea Turtle · G1041
- BlackByte · G1043
- Medusa Group · G1051
Existing anomaly research
Connected anomaly research
Curated research views reached through an exact source technique, a catalog model, or a reviewed collection reference. These are navigation associations, not claims of detector effectiveness or sensor equivalence.
Telemetry contracts · Maintained query examples · Validation and blind spots
Pinned research references. No browser attack runner, live simulation result or validated detector is asserted. Source mappings and validation limits are preserved. ATT&CK / Atomic provenance · Detection provenance.