What is web-shell deployment?¶
Web-shell deployment places server-side code that accepts remote commands or file operations through web requests. Finding the shell establishes a potential foothold, not the original entry route or successful use.
Reconstruct placement¶
Preserve the file, path, hash, timestamps, creator account and process, upload or deployment records and application instance. Possible routes include upload abuse, command injection, stolen administration, vulnerable software or compromised deployment systems.
Replicated servers, containers, images and backups can copy one shell automatically. Compare deployment records and content before interpreting multiple copies as separate intrusions.
Prove shell use separately¶
Correlate web requests and parameters with server processes, commands, files, accounts and outbound connections. Intermittent use may continue after the original vulnerability is patched, and a compromised image can restore the shell during rebuild.
Keep initial access, placement, replication, later command execution and controller attribution as distinct questions.
Key takeaway
Preserve the shell's creation route and replicated copies, then connect requests to server-side effects before concluding it was used or revealed initial access.