Web Shell

Description

Adversaries may backdoor web servers with web shells to establish persistent access to systems. A web shell is a script placed on an openly accessible web server that lets an adversary use the web server as a gateway into a network, providing a command-line interface or file access on the system that hosts the web server. When a web application is vulnerable, an adversary can leverage that weakness to execute commands on the underlying host that serves the application.

Products, Sensors, and Dependencies

ProductDependenciesData sourceAccess requiredProtocolData CollectedNotes
Tenable Web App ScanningWeb ApplicationsRead-onlyAnyWeb Application Vulnerabilities

Attack Path Technique Details

Framework: MITRE ATT&CK

Family: Persistence

Technique: Web Shell

Products Required: Tenable Web App Scanning