Clankerusecase
MITRE ATT&CK detection coverage
← Back to main site
Home/ MITRE Matrix/ Persistence/ T1505.003

T1505.003Web Shell

T1505.003 — Web Shell is a MITRE ATT&CK technique in the Persistence tactic. Clankerusecase tracks 53 detection use cases covering it and 20 threat-intel articles citing it.

Persistence
View on the matrix → Filter Detection Library MITRE official spec ↗
53Use cases
20Articles
0Sub-techniques
1Tactic

Use cases covering this technique (53)

[WEEKLY] Developer/Data-tooling Daemon Spawns Shell Child Seconds After POST to Runner/Exec Endpoint Internal exploit · alerting DSPDD [WEEKLY] Internet-Facing Service Process Spawning Unix Shell or Ingress-Tool LOLBin (Edge Zero-Day Post-Exploit) Internal install · alerting DSΣPDD [WEEKLY] Internet-facing service process spawns shell/LOLBin within minutes of public inbound connection — post-RCE command execution Internal exploit · alerting DSΣPDD [WEEKLY] Post-Auth Privilege Boundary Crossing on Edge/Management Appliances (low-priv -> admin within 10m) Internal exploit · alerting DSPDD [WEEKLY] Self-hosted application service spawns shell or SSH within seconds of inbound unauthenticated API write Internal exploit · alerting DSPDD [WEEKLY] Service-process parent spawns subprocess containing CLI-argument-injection tokens Internal exploit · alerting DSΣPDD [WEEKLY] Web-Server Process Post-Exploit Anchor: Plugin/Extension RCE Leading to Shell Spawn or Webroot Script Drop Internal install · alerting DSΣPDD Detect Exchange Web Shell ESCU actions · alerting P MS Exchange Mailbox Replication service writing Active Server Pages ESCU actions · alerting P Windows Metasploit Confluence Plugin Execution ESCU actions · alerting P Windows Potential Web Shell Creation For VMware Workspace ONE ESCU actions · hunting P Windows SharePoint Spinstall0 Webshell File Creation ESCU actions · alerting P Windows Suspicious Child Process Spawned From WebServer ESCU actions · hunting P Windows TeamCity Payload Execution from Temp Directory ESCU actions · alerting P Windows TeamCity Plugin Installed ESCU actions · hunting P Windows WSUS Spawning Shell ESCU actions · alerting P Cisco Configuration Archive Logging Analysis ESCU actions · hunting P Cisco Secure Firewall - Privileged Command Execution via HTTP ESCU actions · hunting P Exploit Public Facing Application via Apache Commons Text ESCU actions · hunting P Spring4Shell Payload URL Request ESCU actions · alerting P Supernova Webshell ESCU actions · alerting P Tomcat Session Deserialization Attempt ESCU actions · hunting P Tomcat Session File Upload Attempt ESCU actions · hunting P Web JSP Request via URL ESCU actions · alerting P Windows SharePoint Spinstall0 GET Request ESCU actions · alerting P Windows SharePoint ToolPane Endpoint Exploitation Attempt ESCU actions · alerting P Detect Webshell Exploit Behavior ESCU actions · alerting P W3WP Spawning Shell ESCU actions · alerting P [LLM] Write to Splunk .pgpass or ssg_enable_modular_input.py from unexpected process Bespoke install · alerting DSΣPDDCS [LLM] Unexpected .jsp files written under PSEMHUB.war web application Bespoke install · alerting DSΣPDDCS [LLM] PeopleSoft XMLDecoder persistence — XML file changes under envmetadata/data/environment Bespoke install · alerting DSΣPDDCS [LLM] Webserver process writes PHP-executable file to public web-root or upload directory (CVE-2026-48062) Bespoke install · alerting DSΣPDDCS [LLM] Webserver / PHP interpreter spawns shell or LOLBin — post-upload RCE indicator Bespoke exploit · alerting DSΣPDDCS [LLM] HTTP.sys / IIS w3wp.exe spawning shell or LOLBin (CVE-2026-47291 post-exploit) Bespoke exploit · alerting DSΣPDDCS [LLM] Pheditor CVE-2026-48030 — webshell drop: PHP / web account writing .php to webroot Bespoke install · alerting DSΣPDDCS [LLM] Erlang .beam compiled module dropped to /tmp, /dev/shm, or %TEMP% by BEAM runtime Bespoke install · alerting DSΣPDDCS [LLM] w3wp.exe spawning interpreter or LOLBin (http.sys exploitation / IIS RCE marker) Bespoke exploit · alerting DSΣPDDCS [LLM] Web-server process (php-fpm / apache / nginx / w3wp) spawning shell or network tooling Bespoke exploit · hunting DSΣPDDCS [LLM] Phar archive or PHPSpreadsheet RCE marker written by web-server process Bespoke delivery · alerting DSΣPDDCS [LLM] VerdantBamboo BRICKSTORM / PLENET / AGENTPSD file-hash IOCs Bespoke install · hunting DSΣPDDCS [LLM] DbGate Zip Slip (CVE-2026-47669): node process writes outside archive dir to OS-sensitive paths Bespoke install · alerting DSΣPDDCS [LLM] Hazy Scorpius (CL0P) Oracle EBS exploitation via CVE-2025-61882 — concurrent processing spawns shell/wget Bespoke exploit · alerting DSΣPDDCS [LLM] Apache Camel JVM writing files to sensitive paths via camel-file (CVE-2026-47323 arbitrary file write) Bespoke install · hunting DSPDDCS [LLM] Algernon web server spawning shell child process (CVE-2026-45721 handler.lua RCE) Bespoke exploit · alerting DSΣPDDCS [LLM] handler.lua dropped outside Algernon's configured web root (CVE-2026-45721 backdoor stage) Bespoke install · alerting DSΣPDDCS [LLM] PHP / IIS web-server writes .php/.phtml/.phar to webroot (post-SSTI webshell drop) Bespoke install · alerting DSΣPDDCS [LLM] n8n Node.js parent spawning OS shell — post-exploit RCE indicator for CVE-2026-44791 Bespoke exploit · alerting DSΣPDDCS [LLM] XenShell / Godzilla / Behinder JSP webshell file write on Cisco SD-WAN Manager Bespoke install · alerting DSΣPDDCS [LLM] Java/Tomcat process writes .jsp webshell file to disk (CVE-2026-40478 post-exploit drop) Bespoke install · alerting DSΣPDDCS [LLM] Inbound HTTP request bearing sidoraress backdoor x-operation operator tokens Bespoke c2 · alerting SΣPDD [LLM] Compromised tj-actions/changed-files commit SHA referenced on host (CVE-2025-30066 IOC hunt) Bespoke delivery · alerting DSΣPDDCS [LLM] Struts CVE-2023-50164 path-traversal upload — HTTP exploit attempt Bespoke exploit · alerting DSΣPDD [LLM] Tomcat/Java process writes .jsp/.jspx webshell into webapp directory Bespoke install · alerting DSΣPDDCS

Articles citing this technique (20)