ChecklistCONSTRUCTEDUntestedMembers

First 15 minutes: a web server process started a shell

w3wp, httpd, nginx or a Java server spawned cmd, PowerShell or sh. That is a web shell until shown otherwise. Keep the file and the logs, take the server out of the path, and find the request before the first one.

critical severityPersistenceT1505.003T1190

The clock starts when

A web server process (w3wp.exe, httpd, nginx, java or tomcat) starts a shell or a reconnaissance tool, or a new script file appears in a web root.

  1. minutes 0 to 5Record it before anything changes3 lines, 1 where evidence expires
  2. minutes 5 to 10Take it out of the path, not offline3 lines, 1 where evidence expires
  3. minutes 10 to 15Find the way in3 lines

sources

  1. MITRE ATT&CK T1505.003, Server Software Component: Web Shell · primary
  2. NSA Cybersecurity: mitigating web shells (detection and prevention guidance)
  3. CISA Known Exploited Vulnerabilities catalogue
  4. MITRE ATT&CK T1190, Exploit Public-Facing Application

Tags: first-15 · webshell · iis · apache · nginx · exploitation · T1505.003 · T1190