T1505.003Web Shell
T1505.003 — Web Shell is a MITRE ATT&CK technique in the Persistence tactic. Clankerusecase tracks 82 detection use cases covering it and 37 threat-intel articles citing it.
Persistence
82Use cases
37Articles
0Sub-techniques
1Tactic
↑ Parent technique: T1505 · Server Software Component
Use cases covering this technique (82)
[WEEKLY] Developer/Data-tooling Daemon Spawns Shell Child Seconds After POST to Runner/Exec Endpoint [WEEKLY] Internet-Facing Service Process Spawning Unix Shell or Ingress-Tool LOLBin (Edge Zero-Day Post-Exploit) [WEEKLY] Internet-facing service process spawns shell/LOLBin within minutes of public inbound connection — post-RCE command execution [WEEKLY] Post-Auth Privilege Boundary Crossing on Edge/Management Appliances (low-priv -> admin within 10m) [WEEKLY] Self-hosted application service spawns shell or SSH within seconds of inbound unauthenticated API write [WEEKLY] Service-process parent spawns subprocess containing CLI-argument-injection tokens [WEEKLY] Web-Facing Service Process Writes to RCE/Persistence Paths (Path-Traversal File-Write) [WEEKLY] Web-Server Process Post-Exploit Anchor: Plugin/Extension RCE Leading to Shell Spawn or Webroot Script Drop Detect Exchange Web Shell MS Exchange Mailbox Replication service writing Active Server Pages Windows Metasploit Confluence Plugin Execution Windows Potential Web Shell Creation For VMware Workspace ONE Windows SharePoint Spinstall0 Webshell File Creation Windows Suspicious Child Process Spawned From WebServer Windows TeamCity Payload Execution from Temp Directory Windows TeamCity Plugin Installed Windows WSUS Spawning Shell Cisco Configuration Archive Logging Analysis Cisco Secure Firewall - Privileged Command Execution via HTTP Exploit Public Facing Application via Apache Commons Text Spring4Shell Payload URL Request Supernova Webshell Tomcat Session Deserialization Attempt Tomcat Session File Upload Attempt Web JSP Request via URL Windows SharePoint Spinstall0 GET Request Windows SharePoint ToolPane Endpoint Exploitation Attempt Detect Webshell Exploit Behavior W3WP Spawning Shell [LLM] Backdoor payload written to /app by shell/downloader after Ruflo RCE [LLM] Payload or JSP web shell written by the TeamCity server process — CVE-2026-63077 [LLM] vBulletin web-server process (php-fpm/httpd/w3wp) spawning OS shell — CVE-2026-61511 post-exploitation [LLM] Web shell (.jsp/.jspx/.war) written by Java process post-Fastjson RCE [LLM] Cl0p hex-named JSP web shell dropped under /Windchill/login/ (CVE-2026-12569) [LLM] PTC Windchill Java/Tomcat web tier spawning OS command shell (web shell RCE) [LLM] Web-server / PHP process writes new .php file under webroot (post-Pheditor webshell drop) [LLM] Hidden dot-prefixed PHP webshell dropped in web root (.journald-cache.php) [LLM] WordPress web-server/PHP process spawning a shell (wp2shell RCE) [LLM] Malicious PHP plugin/webshell dropped in wp-content by web server (wp2shell) [LLM] WordPress wp2shell batch REST API pre-auth RCE exploitation (CVE-2026-63030/60137) [LLM] New PHP file written into WordPress web root by a web daemon — wp2shell web shell drop [LLM] Pheditor file-upload abuse: web-server process writes new .php webshell [LLM] FacturaScripts: PHP/.htaccess web-shell written into web-served Dinamic/Assets or node_modules [LLM] FacturaScripts RCE chain: .htaccess handler-remap override plus payload drop in same asset dir [LLM] Anyquery process writing files to cron/webroot/SSH persistence paths (ATTACH DATABASE AFW) [LLM] YesWiki webshell drop — web-server process writes new .php file into webroot [LLM] YesWiki wakka.config.php modified by web-server account (post-RCE persistence) [LLM] Compromised web-application server beaconing to espionage C2 (portal-update implant) [LLM] EGroupware header.inc.php overwritten by web process (CVE-2026-27823 RCE persistence) [LLM] EGroupware web runtime (php-fpm/apache) spawning a shell or network tool — CVE-2026-27823 RCE execution [LLM] Web-server process writes PHP file into Mautic config/cache/media/logs (zip-slip landing) [LLM] HTTP request to an executable PHP file under Mautic /media (web-shell interaction) [LLM] Weaponized Twig theme written under Mautic themes/ by web process (CVE-2026-9558) [LLM] LionTail backdoor: DLL search-order hijack via phantom System32 DLLs [LLM] Web shell execution: web server process spawning command interpreters [LLM] Montana Empire kit PHP components staged on web infrastructure [LLM] IIS web shell (w3wp.exe) spawning recon, curl exfil, or RAR staging [LLM] Java/Tomcat process writes .jsp webshell file to disk (CVE-2026-40478 post-exploit drop) [LLM] Spring4Shell JSP webshell drop by Tomcat/Java into webapps (CVE-2022-22965) [LLM] Struts CVE-2023-50164 path-traversal upload — HTTP exploit attempt [LLM] Tomcat/Java process writes .jsp/.jspx webshell into webapp directory [LLM] PHP CLI dev server (php -S) spawning a shell or child interpreter (proc_open php -a) [LLM] Arbitrary file write via '../' in upload 'name' parameter (Mongoose CVE-2022-25299) [LLM] Spring4Shell (CVE-2022-22965) classLoader pipeline injection / JSP webshell call in web logs [LLM] Tomcat/Java process writing a .jsp webshell into webapps (Spring4Shell drop) [LLM] Spring4Shell (CVE-2022-22965) exploit: class.module.classLoader ClassLoader manipulation in HTTP request [LLM] Tomcat/Java writes JSP webshell into webapps (Spring4Shell post-exploit drop) [LLM] Java/Tomcat spawns command shell or download tool (Spring4Shell RCE execution) [LLM] HTTP request to executable PHP inside dompdf font cache (CVE-2022-28368 RCE trigger) [LLM] PHP/web-server process writes .php into dompdf font cache (malicious font staged) [LLM] Magento webshell drop (health_check.php / pub-media PHP) written by web-server process [LLM] SuiteCRM PHAR deserialization via case-mixed phar:// wrapper in admin request [LLM] Direct HTTP 200 to SuiteCRM /upload or /files (post-.htaccess-deletion code exec) [LLM] Node.js process spawning OS command shell (child_process.exec backdoor) [LLM] Inbound web request to Node app with ?cmd= command-injection backdoor parameter [LLM] Installation of malicious npm package 'browser-redirect' (supply-chain backdoor) [LLM] Ghostcat RCE: Tomcat/java process spawning a command shell (JSP webshell execution) [LLM] strong_password 0.0.7 backdoor: RCE via attacker-controlled ___id cookie eval middleware [LLM] bootstrap-sass RCE trigger: base64 Ruby payload smuggled in ___cfduid cookie [LLM] Rails/Ruby app worker (puma/unicorn/passenger) spawning a shell — post-eval RCE [LLM] Zip Slip arbitrary file overwrite by archive-handling runtime (java/python) via path traversal [LLM] Zip Slip: archive-handler process writes shell script / web shell outside extraction dirArticles citing this technique (37)
crit Cl0p Affiliates Target Internet-Exposed PTC Windchill and FlexPLM with Unauthenticated RCE art-75
high SQL injection isn't dead art-118
crit [GHSA / CRITICAL] CVE-2026-9559: Mautic vulnerable to Path Traversal via Campaign Import art-258
high Don't Panic: The Thymeleaf Template Injection That Only Hurts If You Let It (CVE-2026-40478) art-472