BIOCs
Browse the Cortex behavioral indicator of compromise (BIOC) detection rules.
1 BIOC match the current filters. tactic: TA0011 ✕ technique: T1190 ✕
Download CSV Show ATT&CK heatmapExchange process writing aspx files High Infiltration
An exchange process is writing to .aspx files. This may be an actor dropping web shells.
Indicator:File action type = create , write AND file path =~ (\\inetpub\\wwwroot\\aspnet_client\\|\\frontend\\httpproxy\\owa\\auth\\|\\frontend\\httpproxy\\ecp\\auth\\).*\.aspx Process initiated by = UMWorkerProcess.exe , w3wp.exe
ATT&CK tactics: Initial Access (TA0001) Command and Control (TA0011)ATT&CK techniques: Exploit Public-Facing Application (T1190) Application Layer Protocol: Web Protocols (T1071.001)- Preventable:
- Yes
- Source:
- Palo Alto Networks
- Updated:
- 2026-08-23