T1505.003Web Shell
T1505.003 — Web Shell is a MITRE ATT&CK technique in the Persistence tactic. Clankerusecase tracks 76 detection use cases covering it and 29 threat-intel articles citing it.
Persistence
76Use cases
29Articles
0Sub-techniques
1Tactic
↑ Parent technique: T1505 · Server Software Component
Use cases covering this technique (76)
[WEEKLY] Developer/Data-tooling Daemon Spawns Shell Child Seconds After POST to Runner/Exec Endpoint [WEEKLY] Internet-Facing Service Daemon Spawns Shell or Ingress Tool Then Beacons Out [WEEKLY] Internet-Facing Service Process Spawning Unix Shell or Ingress-Tool LOLBin (Edge Zero-Day Post-Exploit) [WEEKLY] Internet-facing service process spawns shell/LOLBin within minutes of public inbound connection — post-RCE command execution [WEEKLY] Post-Auth Privilege Boundary Crossing on Edge/Management Appliances (low-priv -> admin within 10m) [WEEKLY] Public-facing app auth/authz bypass into server-side code execution (patch-bypass wave) [WEEKLY] Public-Facing App Auth-Bypass to Server-Side Code Execution (web-server process spawning a shell/interpreter) [WEEKLY] Self-hosted application service spawns shell or SSH within seconds of inbound unauthenticated API write [WEEKLY] Service-process parent spawns subprocess containing CLI-argument-injection tokens [WEEKLY] Web-Facing Service Process Writes to RCE/Persistence Paths (Path-Traversal File-Write) [WEEKLY] Web-Server Process Post-Exploit Anchor: Plugin/Extension RCE Leading to Shell Spawn or Webroot Script Drop [WEEKLY] Web-tier interpreter post-exploitation: shell/net-tool spawn, secret-file read, or cloud IMDS reach Detect Exchange Web Shell MS Exchange Mailbox Replication service writing Active Server Pages Windows Metasploit Confluence Plugin Execution Windows Potential Web Shell Creation For VMware Workspace ONE Windows SharePoint Spinstall0 Webshell File Creation Windows Suspicious Child Process Spawned From WebServer Windows TeamCity Payload Execution from Temp Directory Windows TeamCity Plugin Installed Windows WSUS Spawning Shell Cisco Configuration Archive Logging Analysis Cisco Secure Firewall - Privileged Command Execution via HTTP Exploit Public Facing Application via Apache Commons Text Spring4Shell Payload URL Request Supernova Webshell Tomcat Session Deserialization Attempt Tomcat Session File Upload Attempt Web JSP Request via URL Windows SharePoint Spinstall0 GET Request Windows SharePoint ToolPane Endpoint Exploitation Attempt Detect Webshell Exploit Behavior W3WP Spawning Shell [LLM] Clop hex-named JSP webshell dropped under PTC Windchill /login (CVE-2026-12569) [LLM] POST to hex-named JSP webshell under /Windchill/login/ in web/proxy logs [LLM] PTC Windchill Java/Tomcat process spawning shell or flst.txt recon [LLM] VMware-impersonating cron jobs drop JSP webshell (vmware-perf-update.jsp) [LLM] ColdFusion server process spawning OS shell / LOLBin (CVE-2026-48362 / CVE-2026-48273 RCE) [LLM] Ruby/Puma Rails web process spawns a shell (post-file-read RCE via forged secret_key_base cookie) [LLM] Web-server / PHP process writes new .php file under webroot (post-Pheditor webshell drop) [LLM] WordPress web-server/PHP process spawning a shell (wp2shell RCE) [LLM] Malicious PHP plugin/webshell dropped in wp-content by web server (wp2shell) [LLM] WordPress wp2shell batch REST API pre-auth RCE exploitation (CVE-2026-63030/60137) [LLM] New PHP file written into WordPress web root by a web daemon — wp2shell web shell drop [LLM] Pheditor file-upload abuse: web-server process writes new .php webshell [LLM] FacturaScripts: PHP/.htaccess web-shell written into web-served Dinamic/Assets or node_modules [LLM] FacturaScripts RCE chain: .htaccess handler-remap override plus payload drop in same asset dir [LLM] Anyquery process writing files to cron/webroot/SSH persistence paths (ATTACH DATABASE AFW) [LLM] YesWiki webshell drop — web-server process writes new .php file into webroot [LLM] YesWiki wakka.config.php modified by web-server account (post-RCE persistence) [LLM] Compromised web-application server beaconing to espionage C2 (portal-update implant) [LLM] Java/Tomcat process writes .jsp webshell file to disk (CVE-2026-40478 post-exploit drop) [LLM] Spring4Shell JSP webshell drop by Tomcat/Java into webapps (CVE-2022-22965) [LLM] Struts CVE-2023-50164 path-traversal upload — HTTP exploit attempt [LLM] Tomcat/Java process writes .jsp/.jspx webshell into webapp directory [LLM] PHP CLI dev server (php -S) spawning a shell or child interpreter (proc_open php -a) [LLM] Arbitrary file write via '../' in upload 'name' parameter (Mongoose CVE-2022-25299) [LLM] Spring4Shell (CVE-2022-22965) classLoader pipeline injection / JSP webshell call in web logs [LLM] Tomcat/Java process writing a .jsp webshell into webapps (Spring4Shell drop) [LLM] Spring4Shell (CVE-2022-22965) exploit: class.module.classLoader ClassLoader manipulation in HTTP request [LLM] Tomcat/Java writes JSP webshell into webapps (Spring4Shell post-exploit drop) [LLM] Java/Tomcat spawns command shell or download tool (Spring4Shell RCE execution) [LLM] HTTP request to executable PHP inside dompdf font cache (CVE-2022-28368 RCE trigger) [LLM] PHP/web-server process writes .php into dompdf font cache (malicious font staged) [LLM] Magento webshell drop (health_check.php / pub-media PHP) written by web-server process [LLM] SuiteCRM PHAR deserialization via case-mixed phar:// wrapper in admin request [LLM] Direct HTTP 200 to SuiteCRM /upload or /files (post-.htaccess-deletion code exec) [LLM] Node.js process spawning OS command shell (child_process.exec backdoor) [LLM] Inbound web request to Node app with ?cmd= command-injection backdoor parameter [LLM] Installation of malicious npm package 'browser-redirect' (supply-chain backdoor) [LLM] Ghostcat RCE: Tomcat/java process spawning a command shell (JSP webshell execution) [LLM] strong_password 0.0.7 backdoor: RCE via attacker-controlled ___id cookie eval middleware [LLM] bootstrap-sass RCE trigger: base64 Ruby payload smuggled in ___cfduid cookie [LLM] Rails/Ruby app worker (puma/unicorn/passenger) spawning a shell — post-eval RCE [LLM] Zip Slip arbitrary file overwrite by archive-handling runtime (java/python) via path traversal [LLM] Zip Slip: archive-handler process writes shell script / web shell outside extraction dirArticles citing this technique (29)
crit Suspected China-Nexus Actor Exploits VMware vCenter Flaw, Deploys Babuk-Derived Ransomware art-28
high SQL injection isn't dead art-224
high Don't Panic: The Thymeleaf Template Injection That Only Hurts If You Let It (CVE-2026-40478) art-517