Skip to content
Skip to main content
Cyber Incidents & Offender Methods Technical Explainer

How can a web shell provide persistence?

A web shell can leave a remotely accessible command mechanism after the vulnerability or account used to place it has been closed. Patching the initial weakness and removing the shell address different parts of the incident.

Preserve the mechanism and its use

Retain the shell code, path, hashes and timestamps before deletion. Correlate web requests and parameters with server processes, commands, files, accounts and network connections to establish whether it was used.

The shell may be renamed, altered or hidden inside legitimate application code. Presence proves an available route, not continued access; request and process evidence demonstrate operation.

Account for replicated environments

Applications may run on several servers, containers or restored images. Deployment, replication and backup records can show whether multiple copies were propagated automatically or installed separately by an offender.

Removing one copy may leave others reachable or allow a normal deployment process to restore the file. Identify every affected instance and preserve routing records that connect requests to them. This prevents normal replication being misreported as repeated attacker action while ensuring the complete persistence route is contained.

Key takeaway

Treat the web shell as an independent foothold: preserve its code and use evidence, map replicated copies, and do not assume patching the original flaw removed it.

Reference: CIM-116Cyber Incidents & Offender Methods