Clankerusecase
MITRE ATT&CK detection coverage
← Back to main site
Home/ MITRE Matrix/ Persistence/ T1505.003

T1505.003Web Shell

T1505.003 — Web Shell is a MITRE ATT&CK technique in the Persistence tactic. Clankerusecase tracks 76 detection use cases covering it and 29 threat-intel articles citing it.

Persistence
View on the matrix → Filter Detection Library MITRE official spec ↗
76Use cases
29Articles
0Sub-techniques
1Tactic

Use cases covering this technique (76)

[WEEKLY] Developer/Data-tooling Daemon Spawns Shell Child Seconds After POST to Runner/Exec Endpoint Internal exploit · alerting DSPDD [WEEKLY] Internet-Facing Service Daemon Spawns Shell or Ingress Tool Then Beacons Out Internal exploit · alerting DSΣPDDCS [WEEKLY] Internet-Facing Service Process Spawning Unix Shell or Ingress-Tool LOLBin (Edge Zero-Day Post-Exploit) Internal install · alerting DSΣPDD [WEEKLY] Internet-facing service process spawns shell/LOLBin within minutes of public inbound connection — post-RCE command execution Internal exploit · alerting DSΣPDD [WEEKLY] Post-Auth Privilege Boundary Crossing on Edge/Management Appliances (low-priv -> admin within 10m) Internal exploit · alerting DSPDD [WEEKLY] Public-facing app auth/authz bypass into server-side code execution (patch-bypass wave) Internal exploit · alerting DSΣPDDCS [WEEKLY] Public-Facing App Auth-Bypass to Server-Side Code Execution (web-server process spawning a shell/interpreter) Internal exploit · alerting DSΣPDDCS [WEEKLY] Self-hosted application service spawns shell or SSH within seconds of inbound unauthenticated API write Internal exploit · alerting DSPDD [WEEKLY] Service-process parent spawns subprocess containing CLI-argument-injection tokens Internal exploit · alerting DSΣPDD [WEEKLY] Web-Facing Service Process Writes to RCE/Persistence Paths (Path-Traversal File-Write) Internal install · alerting DSΣPDDCS [WEEKLY] Web-Server Process Post-Exploit Anchor: Plugin/Extension RCE Leading to Shell Spawn or Webroot Script Drop Internal install · alerting DSΣPDD [WEEKLY] Web-tier interpreter post-exploitation: shell/net-tool spawn, secret-file read, or cloud IMDS reach Internal install · alerting DSΣPDDCSCW Detect Exchange Web Shell ESCU actions · alerting P MS Exchange Mailbox Replication service writing Active Server Pages ESCU actions · alerting P Windows Metasploit Confluence Plugin Execution ESCU actions · alerting P Windows Potential Web Shell Creation For VMware Workspace ONE ESCU actions · hunting P Windows SharePoint Spinstall0 Webshell File Creation ESCU actions · alerting P Windows Suspicious Child Process Spawned From WebServer ESCU actions · hunting P Windows TeamCity Payload Execution from Temp Directory ESCU actions · alerting P Windows TeamCity Plugin Installed ESCU actions · hunting P Windows WSUS Spawning Shell ESCU actions · alerting P Cisco Configuration Archive Logging Analysis ESCU actions · hunting P Cisco Secure Firewall - Privileged Command Execution via HTTP ESCU actions · hunting P Exploit Public Facing Application via Apache Commons Text ESCU actions · hunting P Spring4Shell Payload URL Request ESCU actions · alerting P Supernova Webshell ESCU actions · alerting P Tomcat Session Deserialization Attempt ESCU actions · hunting P Tomcat Session File Upload Attempt ESCU actions · hunting P Web JSP Request via URL ESCU actions · alerting P Windows SharePoint Spinstall0 GET Request ESCU actions · alerting P Windows SharePoint ToolPane Endpoint Exploitation Attempt ESCU actions · alerting P Detect Webshell Exploit Behavior ESCU actions · alerting P W3WP Spawning Shell ESCU actions · alerting P [LLM] Clop hex-named JSP webshell dropped under PTC Windchill /login (CVE-2026-12569) Bespoke install · alerting DSΣPDDCS [LLM] POST to hex-named JSP webshell under /Windchill/login/ in web/proxy logs Bespoke exploit · hunting SΣP [LLM] PTC Windchill Java/Tomcat process spawning shell or flst.txt recon Bespoke exploit · alerting DSΣPDDCS [LLM] VMware-impersonating cron jobs drop JSP webshell (vmware-perf-update.jsp) Bespoke install · alerting DSΣPDDCS [LLM] ColdFusion server process spawning OS shell / LOLBin (CVE-2026-48362 / CVE-2026-48273 RCE) Bespoke exploit · hunting DSΣPDDCS [LLM] Ruby/Puma Rails web process spawns a shell (post-file-read RCE via forged secret_key_base cookie) Bespoke exploit · alerting DSΣPCS [LLM] Web-server / PHP process writes new .php file under webroot (post-Pheditor webshell drop) Bespoke install · hunting DSΣPDDCS [LLM] WordPress web-server/PHP process spawning a shell (wp2shell RCE) Bespoke exploit · alerting DSΣPDDCS [LLM] Malicious PHP plugin/webshell dropped in wp-content by web server (wp2shell) Bespoke install · hunting DSΣPDDCS [LLM] WordPress wp2shell batch REST API pre-auth RCE exploitation (CVE-2026-63030/60137) Bespoke exploit · alerting SΣP [LLM] New PHP file written into WordPress web root by a web daemon — wp2shell web shell drop Bespoke install · hunting DSΣPDDCS [LLM] Pheditor file-upload abuse: web-server process writes new .php webshell Bespoke install · alerting DSΣPDDCS [LLM] FacturaScripts: PHP/.htaccess web-shell written into web-served Dinamic/Assets or node_modules Bespoke install · alerting DSΣPDDCS [LLM] FacturaScripts RCE chain: .htaccess handler-remap override plus payload drop in same asset dir Bespoke exploit · alerting DSPCS [LLM] Anyquery process writing files to cron/webroot/SSH persistence paths (ATTACH DATABASE AFW) Bespoke install · alerting DSΣPCS [LLM] YesWiki webshell drop — web-server process writes new .php file into webroot Bespoke install · alerting DSΣPDDCS [LLM] YesWiki wakka.config.php modified by web-server account (post-RCE persistence) Bespoke install · alerting DSΣPDDCS [LLM] Compromised web-application server beaconing to espionage C2 (portal-update implant) Bespoke c2 · hunting DSΣPDDCS [LLM] Java/Tomcat process writes .jsp webshell file to disk (CVE-2026-40478 post-exploit drop) Bespoke install · alerting DSΣPDDCS [LLM] Spring4Shell JSP webshell drop by Tomcat/Java into webapps (CVE-2022-22965) Bespoke install · alerting DSΣPDDCS [LLM] Struts CVE-2023-50164 path-traversal upload — HTTP exploit attempt Bespoke exploit · alerting DSΣPDD [LLM] Tomcat/Java process writes .jsp/.jspx webshell into webapp directory Bespoke install · alerting DSΣPDDCS [LLM] PHP CLI dev server (php -S) spawning a shell or child interpreter (proc_open php -a) Bespoke exploit · alerting DSΣPDDCS [LLM] Arbitrary file write via '../' in upload 'name' parameter (Mongoose CVE-2022-25299) Bespoke install · alerting DSΣPCS [LLM] Spring4Shell (CVE-2022-22965) classLoader pipeline injection / JSP webshell call in web logs Bespoke exploit · alerting SΣP [LLM] Tomcat/Java process writing a .jsp webshell into webapps (Spring4Shell drop) Bespoke install · alerting DSΣPDDCS [LLM] Spring4Shell (CVE-2022-22965) exploit: class.module.classLoader ClassLoader manipulation in HTTP request Bespoke exploit · alerting SΣP [LLM] Tomcat/Java writes JSP webshell into webapps (Spring4Shell post-exploit drop) Bespoke install · alerting DSΣPDDCS [LLM] Java/Tomcat spawns command shell or download tool (Spring4Shell RCE execution) Bespoke exploit · alerting DSΣPDDCS [LLM] HTTP request to executable PHP inside dompdf font cache (CVE-2022-28368 RCE trigger) Bespoke exploit · alerting SΣP [LLM] PHP/web-server process writes .php into dompdf font cache (malicious font staged) Bespoke install · hunting DSΣPCS [LLM] Magento webshell drop (health_check.php / pub-media PHP) written by web-server process Bespoke install · alerting DSΣPCS [LLM] SuiteCRM PHAR deserialization via case-mixed phar:// wrapper in admin request Bespoke exploit · alerting SΣP [LLM] Direct HTTP 200 to SuiteCRM /upload or /files (post-.htaccess-deletion code exec) Bespoke actions · hunting SΣP [LLM] Node.js process spawning OS command shell (child_process.exec backdoor) Bespoke install · hunting DSΣPDDCS [LLM] Inbound web request to Node app with ?cmd= command-injection backdoor parameter Bespoke c2 · hunting SP [LLM] Installation of malicious npm package 'browser-redirect' (supply-chain backdoor) Bespoke delivery · hunting DSΣPDDCS [LLM] Ghostcat RCE: Tomcat/java process spawning a command shell (JSP webshell execution) Bespoke exploit · hunting DSΣPDDCS [LLM] strong_password 0.0.7 backdoor: RCE via attacker-controlled ___id cookie eval middleware Bespoke exploit · alerting SΣP [LLM] bootstrap-sass RCE trigger: base64 Ruby payload smuggled in ___cfduid cookie Bespoke exploit · hunting SP [LLM] Rails/Ruby app worker (puma/unicorn/passenger) spawning a shell — post-eval RCE Bespoke actions · hunting DSΣPCS [LLM] Zip Slip arbitrary file overwrite by archive-handling runtime (java/python) via path traversal Bespoke exploit · hunting DSΣPDDCS [LLM] Zip Slip: archive-handler process writes shell script / web shell outside extraction dir Bespoke install · hunting DSΣPDDCS

Articles citing this technique (29)