Skip to content
Skip to main content
Cyber Incidents & Offender Methods Technical Explainer

What is a backdoor?

A backdoor is a concealed access mechanism deliberately placed, modified or retained to bypass or supplement a system's normal access controls.

It may be malware, a hidden account, a modified service, a secret command, a web shell or a deliberately weakened configuration. An ordinary vulnerability or accidental misconfiguration may provide an entry route, but that does not automatically make it a backdoor. The distinction is whether someone deliberately established or retained the mechanism as a concealed route for access.

A web shell shows the route clearly

Suppose an organisation finds an unfamiliar script in a Microsoft IIS web directory. Web-server logs record a request to that script. Endpoint telemetry then shows the IIS worker process creating a command-shell child process, followed by file and network activity.

External requestWeb log records the script pathTime, source, method, result and request details describe the approach.
Concealed routeIIS handles the unfamiliar scriptFile, deployment and change records explain how it appeared.
Command executionThe web worker starts a shellParent-child process evidence connects the request to system activity.
EffectFiles or connections followResulting records show what the access route was used to do.

That joined sequence can establish use of the backdoor. Finding the script alone establishes the route's presence and potential capability, not a completed remote session.

Describe the mechanism precisely

Different backdoors leave different evidence:

Mechanism Evidence that may explain it Use evidence to seek
Web shell Server file, deployment/change history, web logs and worker-process activity Requests, child processes, commands and resulting changes
Hidden account Account creation, role/group change and authentication records Sign-ins, sessions and actions through the account
Modified service or task Configuration, executable/script and creator process Trigger, process start and subsequent activity
Secret application command Code/configuration and required input or source condition Matching requests and resulting function
Misused admin feature Product setting, authorised baseline and changing actor Sessions and actions through the feature

Avoid reporting only that “a backdoor existed”. State the access route, prerequisites, privileges, whether it persisted and the observable result.

Creation, use and control can involve different actors

One person or automated malware may create the route and another may use it later. A compromised administrator account may install it without the account holder's knowledge. An external address may identify an intermediary rather than the operator.

Build separate propositions for:

  1. when and how the backdoor was created;
  2. what access it was capable of providing;
  3. whether it was activated or used;
  4. what happened during that use; and
  5. which account, infrastructure, device or person controlled each stage.

These distinctions allow a strong finding about unauthorised access without overstating personal attribution.

Preserve the route before removing it

Containment may be urgent, but capture the file or configuration, relevant logs, process relationships, network state and timestamps where safe and authorised. Record every response action so later reviewers can distinguish incident changes from remediation.

A backdoor can also survive a password reset if it uses its own account, service or code path. The persistence guidance explains how to test whether an access mechanism survived restart or interruption. A remote-access tool may offer similar capability through legitimate software; its authority, configuration and sessions determine the interpretation.

Describe the mechanism rather than relying on the label. A confirmed backdoor establishes a concealed access route; the request, session, process and resulting records establish whether it was used and what happened through it.

Technical sources - checked 27 September 2026
Reference: CIM-070Cyber Incidents & Offender Methods