1200KM / simulation
T1505.003 Web Shell — Attack Simulation
Adversaries may backdoor web servers with web shells to establish persistent access to systems. A Web shell is a Web script that is placed on an openly accessible Web server to allow an adversary to access the Web server as a gateway into a network. A Web shell may provide a set of functions to execute or a command-line interface on the system that hosts the Web server. In addition to a server-side script, a Web shell may have a client interface…
Technique description
Adversaries may backdoor web servers with web shells to establish persistent access to systems. A Web shell is a Web script that is placed on an openly accessible Web server to allow an adversary to access the Web server as a gateway into a network. A Web shell may provide a set of functions to execute or a command-line interface on the system that hosts the Web server. In addition to a server-side script, a Web shell may have a client interface…
At least one platform-compatible Atomic procedure is documented. Individual review, lab prerequisites, and validation remain required.
Official ATT&CK definition · Detection rules and anomaly models
Documented simulation candidates
- Web Shell Written to Disk
Procedure 0a2ce662-1efa-496f-a472-2fe7b080db16; elevation not declared required; cleanup present, not reviewed. Not executed or individually validated.
Connected ecosystem references
Linked tags
Detection and collection
Attack tools
No reviewed association in this snapshot.
Threat actor context
These are explicit actor-to-technique associations in the existing Threat Matrix snapshot, not attribution of an event or proof that a detector identifies the actor. No tool-to-actor relationship is inferred.
- APT28 · G0007
- Deep Panda · G0009
- APT29 · G0016
- Threat Group-3390 · G0027
- Sandworm Team · G0034
- Dragonfly · G0035
- OilRig · G0049
- APT32 · G0050
- Magic Hound · G0059
- Leviathan · G0065
- Tropic Trooper · G0081
- APT38 · G0082
- APT39 · G0087
- GALLIUM · G0093
- Kimsuky · G0094
- Fox Kitten · G0117
- Volatile Cedar · G0123
- HAFNIUM · G0125
- Mustang Panda · G0129
- Tonto Team · G0131
- BackdoorDiplomacy · G0135
- Ember Bear · G1003
- Moses Staff · G1009
- CURIUM · G1012
- FIN13 · G1016
- Volt Typhoon · G1017
- APT5 · G1023
- Agrius · G1030
- Sea Turtle · G1041
- BlackByte · G1043
- Medusa Group · G1051
Existing research
Connected anomaly research
Curated research views reached through an exact source technique, a catalog model, or a reviewed collection reference. These are navigation associations, not claims of detector effectiveness or sensor equivalence.
Telemetry contracts · Maintained query examples · Validation and blind spots
Pinned research references. No browser attack runner, live simulation result or validated detector is asserted. Source mappings and validation limits are preserved. ATT&CK / Atomic provenance · Detection provenance.