Skip to content
Skip to main content
Cyber Incidents & Offender Methods Technical Explainer

What is web-shell deployment?

Web-shell deployment places server-side code that accepts remote commands or file operations through web requests. Finding the shell establishes a potential foothold, not the original entry route or successful use.

Reconstruct placement

Preserve the file, path, hash, timestamps, creator account and process, upload or deployment records and application instance. Possible routes include upload abuse, command injection, stolen administration, vulnerable software or compromised deployment systems.

Replicated servers, containers, images and backups can copy one shell automatically. Compare deployment records and content before interpreting multiple copies as separate intrusions.

Prove shell use separately

Correlate web requests and parameters with server processes, commands, files, accounts and outbound connections. Intermittent use may continue after the original vulnerability is patched, and a compromised image can restore the shell during rebuild.

Keep initial access, placement, replication, later command execution and controller attribution as distinct questions.

Key takeaway

Preserve the shell's creation route and replicated copies, then connect requests to server-side effects before concluding it was used or revealed initial access.

Reference: CIM-215Cyber Incidents & Offender Methods