Analytics
Informational
✕
Web server CGO executed a process following a potential Webshell dropped
A process was executed by a web server CGO following a potential drop of a webshell file.
- Module:
- Platform Analytics
- Data source:
- XDR Agent with eXtended Threat Hunting (XTH)
ATT&CK tactics: Persistence (TA0003)
ATT&CK techniques: Server Software Component: Web Shell (T1505.003)
Detector tags: Webshell Analytics
Attacker's goals:
Gaining the ability to execute commands on the host, as well as persistence.
Investigative actions:
Investigate the web server access logs for suspicious behavior. Check if the dropped file contains malicious content.
- Test period:
- 4 Hours
- Deduplication:
- 1 Day