Clankerusecase
MITRE ATT&CK detection coverage
← Back to main site
Home/ MITRE Matrix/ Persistence/ T1505.003

T1505.003Web Shell

T1505.003 — Web Shell is a MITRE ATT&CK technique in the Persistence tactic. Clankerusecase tracks 82 detection use cases covering it and 37 threat-intel articles citing it.

Persistence
View on the matrix → Filter Detection Library MITRE official spec ↗
82Use cases
37Articles
0Sub-techniques
1Tactic

Use cases covering this technique (82)

[WEEKLY] Developer/Data-tooling Daemon Spawns Shell Child Seconds After POST to Runner/Exec Endpoint Internal exploit · alerting DSPDD [WEEKLY] Internet-Facing Service Process Spawning Unix Shell or Ingress-Tool LOLBin (Edge Zero-Day Post-Exploit) Internal install · alerting DSΣPDD [WEEKLY] Internet-facing service process spawns shell/LOLBin within minutes of public inbound connection — post-RCE command execution Internal exploit · alerting DSΣPDD [WEEKLY] Post-Auth Privilege Boundary Crossing on Edge/Management Appliances (low-priv -> admin within 10m) Internal exploit · alerting DSPDD [WEEKLY] Self-hosted application service spawns shell or SSH within seconds of inbound unauthenticated API write Internal exploit · alerting DSPDD [WEEKLY] Service-process parent spawns subprocess containing CLI-argument-injection tokens Internal exploit · alerting DSΣPDD [WEEKLY] Web-Facing Service Process Writes to RCE/Persistence Paths (Path-Traversal File-Write) Internal install · alerting DSΣPDDCS [WEEKLY] Web-Server Process Post-Exploit Anchor: Plugin/Extension RCE Leading to Shell Spawn or Webroot Script Drop Internal install · alerting DSΣPDD Detect Exchange Web Shell ESCU actions · alerting P MS Exchange Mailbox Replication service writing Active Server Pages ESCU actions · alerting P Windows Metasploit Confluence Plugin Execution ESCU actions · alerting P Windows Potential Web Shell Creation For VMware Workspace ONE ESCU actions · hunting P Windows SharePoint Spinstall0 Webshell File Creation ESCU actions · alerting P Windows Suspicious Child Process Spawned From WebServer ESCU actions · hunting P Windows TeamCity Payload Execution from Temp Directory ESCU actions · alerting P Windows TeamCity Plugin Installed ESCU actions · hunting P Windows WSUS Spawning Shell ESCU actions · alerting P Cisco Configuration Archive Logging Analysis ESCU actions · hunting P Cisco Secure Firewall - Privileged Command Execution via HTTP ESCU actions · hunting P Exploit Public Facing Application via Apache Commons Text ESCU actions · hunting P Spring4Shell Payload URL Request ESCU actions · alerting P Supernova Webshell ESCU actions · alerting P Tomcat Session Deserialization Attempt ESCU actions · hunting P Tomcat Session File Upload Attempt ESCU actions · hunting P Web JSP Request via URL ESCU actions · alerting P Windows SharePoint Spinstall0 GET Request ESCU actions · alerting P Windows SharePoint ToolPane Endpoint Exploitation Attempt ESCU actions · alerting P Detect Webshell Exploit Behavior ESCU actions · alerting P W3WP Spawning Shell ESCU actions · alerting P [LLM] Backdoor payload written to /app by shell/downloader after Ruflo RCE Bespoke install · hunting DSΣPDDCS [LLM] Payload or JSP web shell written by the TeamCity server process — CVE-2026-63077 Bespoke install · hunting DSΣPDDCS [LLM] vBulletin web-server process (php-fpm/httpd/w3wp) spawning OS shell — CVE-2026-61511 post-exploitation Bespoke actions · alerting DSΣPDDCS [LLM] Web shell (.jsp/.jspx/.war) written by Java process post-Fastjson RCE Bespoke install · alerting DSΣPDDCS [LLM] Cl0p hex-named JSP web shell dropped under /Windchill/login/ (CVE-2026-12569) Bespoke install · hunting DSΣPDDCS [LLM] PTC Windchill Java/Tomcat web tier spawning OS command shell (web shell RCE) Bespoke exploit · alerting DSΣPDDCS [LLM] Web-server / PHP process writes new .php file under webroot (post-Pheditor webshell drop) Bespoke install · hunting DSΣPDDCS [LLM] Hidden dot-prefixed PHP webshell dropped in web root (.journald-cache.php) Bespoke install · alerting DSΣPCS [LLM] WordPress web-server/PHP process spawning a shell (wp2shell RCE) Bespoke exploit · alerting DSΣPDDCS [LLM] Malicious PHP plugin/webshell dropped in wp-content by web server (wp2shell) Bespoke install · hunting DSΣPDDCS [LLM] WordPress wp2shell batch REST API pre-auth RCE exploitation (CVE-2026-63030/60137) Bespoke exploit · alerting SΣP [LLM] New PHP file written into WordPress web root by a web daemon — wp2shell web shell drop Bespoke install · hunting DSΣPDDCS [LLM] Pheditor file-upload abuse: web-server process writes new .php webshell Bespoke install · alerting DSΣPDDCS [LLM] FacturaScripts: PHP/.htaccess web-shell written into web-served Dinamic/Assets or node_modules Bespoke install · alerting DSΣPDDCS [LLM] FacturaScripts RCE chain: .htaccess handler-remap override plus payload drop in same asset dir Bespoke exploit · alerting DSPCS [LLM] Anyquery process writing files to cron/webroot/SSH persistence paths (ATTACH DATABASE AFW) Bespoke install · alerting DSΣPCS [LLM] YesWiki webshell drop — web-server process writes new .php file into webroot Bespoke install · alerting DSΣPDDCS [LLM] YesWiki wakka.config.php modified by web-server account (post-RCE persistence) Bespoke install · alerting DSΣPDDCS [LLM] Compromised web-application server beaconing to espionage C2 (portal-update implant) Bespoke c2 · hunting DSΣPDDCS [LLM] EGroupware header.inc.php overwritten by web process (CVE-2026-27823 RCE persistence) Bespoke install · alerting DSΣPCS [LLM] EGroupware web runtime (php-fpm/apache) spawning a shell or network tool — CVE-2026-27823 RCE execution Bespoke actions · hunting DSΣPCS [LLM] Web-server process writes PHP file into Mautic config/cache/media/logs (zip-slip landing) Bespoke install · alerting DSΣPCS [LLM] HTTP request to an executable PHP file under Mautic /media (web-shell interaction) Bespoke c2 · alerting SP [LLM] Weaponized Twig theme written under Mautic themes/ by web process (CVE-2026-9558) Bespoke install · hunting DSΣPDDCS [LLM] LionTail backdoor: DLL search-order hijack via phantom System32 DLLs Bespoke install · alerting DSΣPDDCS [LLM] Web shell execution: web server process spawning command interpreters Bespoke exploit · alerting DSΣPDDCS [LLM] Montana Empire kit PHP components staged on web infrastructure Bespoke install · hunting DSΣPDDCS [LLM] IIS web shell (w3wp.exe) spawning recon, curl exfil, or RAR staging Bespoke exploit · hunting DSΣPDDCS [LLM] Java/Tomcat process writes .jsp webshell file to disk (CVE-2026-40478 post-exploit drop) Bespoke install · alerting DSΣPDDCS [LLM] Spring4Shell JSP webshell drop by Tomcat/Java into webapps (CVE-2022-22965) Bespoke install · alerting DSΣPDDCS [LLM] Struts CVE-2023-50164 path-traversal upload — HTTP exploit attempt Bespoke exploit · alerting DSΣPDD [LLM] Tomcat/Java process writes .jsp/.jspx webshell into webapp directory Bespoke install · alerting DSΣPDDCS [LLM] PHP CLI dev server (php -S) spawning a shell or child interpreter (proc_open php -a) Bespoke exploit · alerting DSΣPDDCS [LLM] Arbitrary file write via '../' in upload 'name' parameter (Mongoose CVE-2022-25299) Bespoke install · alerting DSΣPCS [LLM] Spring4Shell (CVE-2022-22965) classLoader pipeline injection / JSP webshell call in web logs Bespoke exploit · alerting SΣP [LLM] Tomcat/Java process writing a .jsp webshell into webapps (Spring4Shell drop) Bespoke install · alerting DSΣPDDCS [LLM] Spring4Shell (CVE-2022-22965) exploit: class.module.classLoader ClassLoader manipulation in HTTP request Bespoke exploit · alerting SΣP [LLM] Tomcat/Java writes JSP webshell into webapps (Spring4Shell post-exploit drop) Bespoke install · alerting DSΣPDDCS [LLM] Java/Tomcat spawns command shell or download tool (Spring4Shell RCE execution) Bespoke exploit · alerting DSΣPDDCS [LLM] HTTP request to executable PHP inside dompdf font cache (CVE-2022-28368 RCE trigger) Bespoke exploit · alerting SΣP [LLM] PHP/web-server process writes .php into dompdf font cache (malicious font staged) Bespoke install · hunting DSΣPCS [LLM] Magento webshell drop (health_check.php / pub-media PHP) written by web-server process Bespoke install · alerting DSΣPCS [LLM] SuiteCRM PHAR deserialization via case-mixed phar:// wrapper in admin request Bespoke exploit · alerting SΣP [LLM] Direct HTTP 200 to SuiteCRM /upload or /files (post-.htaccess-deletion code exec) Bespoke actions · hunting SΣP [LLM] Node.js process spawning OS command shell (child_process.exec backdoor) Bespoke install · hunting DSΣPDDCS [LLM] Inbound web request to Node app with ?cmd= command-injection backdoor parameter Bespoke c2 · hunting SP [LLM] Installation of malicious npm package 'browser-redirect' (supply-chain backdoor) Bespoke delivery · hunting DSΣPDDCS [LLM] Ghostcat RCE: Tomcat/java process spawning a command shell (JSP webshell execution) Bespoke exploit · hunting DSΣPDDCS [LLM] strong_password 0.0.7 backdoor: RCE via attacker-controlled ___id cookie eval middleware Bespoke exploit · alerting SΣP [LLM] bootstrap-sass RCE trigger: base64 Ruby payload smuggled in ___cfduid cookie Bespoke exploit · hunting SP [LLM] Rails/Ruby app worker (puma/unicorn/passenger) spawning a shell — post-eval RCE Bespoke actions · hunting DSΣPCS [LLM] Zip Slip arbitrary file overwrite by archive-handling runtime (java/python) via path traversal Bespoke exploit · hunting DSΣPDDCS [LLM] Zip Slip: archive-handler process writes shell script / web shell outside extraction dir Bespoke install · hunting DSΣPDDCS

Articles citing this technique (37)