LiveActive security incident?Get immediate response
MITRE ATT&CK® Technique

T1505.003: Web Shell

Adversaries may backdoor web servers with web shells to establish persistent access to systems. A Web shell is a Web script that is placed on an openly accessible Web server to allow an adversary to access the Web server as a gateway into a network. A Web shell may provide a set of functions to execute or a command-line interface on the system that hosts the Web server.Citationvolexity_0day_sophos_FW

In addition to a server-side script, a Web shell may have a client interface program that is used to talk to the Web server (e.g. China Chopper Web shell client).CitationLee 2013

EnterpriseT1505.003Sub-techniqueObject v1.5Modified
Glexia's Take · Automated analysis

Security context for executives and security teams

Automation confidenceHigh

Web shells matter because they turn an exposed web server, application, or network device management interface into a persistent doorway. For leaders, the key issue is not just malware on a server; it is whether an Internet-facing system can become a durable gateway into internal operations, credentials, sensitive data, or cyber-physical environments. ATT&CK links this technique to multiple campaigns and groups, including activity involving vulnerable public-facing applications, VPN/SD-WAN appliances, government networks, utilities, MSPs, and industrial-adjacent environments, so coverage should be treated as a resilience and incident-readiness priority.

Executive priority

Prioritize web shell readiness where externally reachable servers, server software components, and network devices support critical business processes. Ask whether teams can prove three things: unauthorized files or scripts in web-accessible locations are detected, web server processes spawning unusual execution chains are investigated quickly, and unnecessary server features or privileged accounts are reduced. This technique is especially relevant to vulnerability prioritization because several related campaigns describe exploitation of vulnerable Internet-facing services or appliances before persistence. It also supports compliance evidence: organizations should be able to show account lifecycle control, least privilege, service reduction, logging, and incident response procedures for exposed server software.

Technical view

T1505.003 is a persistence sub-technique of Server Software Component across Linux, macOS, Windows, and Network Devices. Since MITRE does not provide native detection text for this object, validation should be anchored to the related detection strategy DET0394, Web Shell Detection via Server Behavior and File Execution Chains. SOC and IR teams should test whether they can correlate new or modified web-accessible scripts with web server access patterns, child process creation from web server service accounts, command execution behavior, and outbound connections initiated by the hosting server. Because the object is persistence-focused, triage should include whether the web shell is a foothold into broader lateral movement, credential access, or operational systems, but those conclusions require local evidence.

Likely telemetry

  • Web server access logs and error logs for requests to unusual, newly created, or rarely used script paths
  • File creation, modification, and integrity monitoring for web roots, plug-in directories, upload paths, and server extension locations
  • Process execution telemetry showing web server or application server processes launching shells, interpreters, utilities, or other unexpected child processes
  • Command-line and script execution logs on Linux, macOS, Windows, and supported network device platforms where available
  • Network telemetry for unexpected inbound access patterns and outbound connections from web servers or management appliances

Detection direction

  • Validate DET0394-style coverage by testing for the chain: web request, server-side script access, file write or modification, and execution spawned by the web server process.
  • Tune detections around server behavior rather than filename alone; web shells may be simple server-side scripts and may use a separate client interface such as China Chopper.
  • Baseline legitimate administrative scripts, deployment pipelines, web application upload behavior, and maintenance activity to reduce false positives.
  • Prioritize high-severity triage for detections on Internet-facing servers, network devices, MSP/service-provider infrastructure, and systems that bridge to sensitive or operational environments.
  • Hunt historical logs after exposure of relevant vulnerable public-facing applications or appliances, because persistence may remain after the initial vulnerability is patched.

Mitigation priorities

  • Reduce exposed server attack surface by disabling or removing unnecessary features, services, components, legacy software, and unused web application functionality, aligned to M1042.
  • Strengthen user account management for web server administrators, service accounts, and application identities, including least privilege and account lifecycle controls, aligned to M1018.
  • Use vulnerability and asset management to identify Internet-facing servers and network devices that require urgent patching, configuration review, or compensating monitoring.
  • Maintain file integrity monitoring and controlled deployment processes for web-accessible directories so unauthorized scripts are easier to distinguish from approved changes.
  • Prepare IR procedures for suspected web shells: preserve web logs and file timestamps, review server process execution, identify account misuse, and scope whether the server acted as a gateway into the network.
Additional notes and limits

The relationship set makes this technique material beyond ordinary web malware: it is used by numerous ATT&CK-tracked campaigns and groups, and several campaign descriptions reference exploitation of public-facing services, appliances, or environments with operational significance. The strongest defensive decision is to treat web shell coverage as a combined exposure-management, logging, detection-engineering, and incident-response problem rather than as a single signature requirement.

The official ATT&CK object does not include a detection description, so detection guidance is derived from the supplied relationship to DET0394 and the official technique description. Relationship descriptions are partial in several cases, so this take does not infer specific procedures, indicators, affected products, or current exploitation beyond what is supplied. Local asset inventory, logging depth, application architecture, and appliance telemetry determine actual coverage.

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Official MITRE ATT&CK definition

Web Shell

Adversaries may backdoor web servers with web shells to establish persistent access to systems. A Web shell is a Web script that is placed on an openly accessible Web server to allow an adversary to access the Web server as a gateway into a network. A Web shell may provide a set of functions to execute or a command-line interface on the system that hosts the Web server.Citationvolexity_0day_sophos_FW

In addition to a server-side script, a Web shell may have a client interface program that is used to talk to the Web server (e.g. China Chopper Web shell client).CitationLee 2013

View the same entry on attack.mitre.org (MITRE-hosted reference; in-page links above use the Glexia ATT&CK library.)

Glexia analysis

How security teams should use this page

Treat this object as behavior context, not an attribution claim. Validate the related groups, software, data sources, and mitigations against official ATT&CK relationships and your own telemetry before making control-coverage decisions.

Relationship explorer

All related ATT&CK context

No relationships are available in the current normalized data for this object.

Change history

Object version and sync metadata

The fields below describe the current mirrored snapshot. When Glexia retains multiple ATT&CK source imports, you can open the table to compare the same object across releases (hashes and MITRE timestamps). For MITRE’s own release notes and roadmap, see ATT&CK resources — Updates.

ATT&CK release
19.1
Object version
1.5
Created
Modified
Raw hash
4a4a92fabf65d98d...
Raw source

Mirrored ATT&CK source object

The raw object is retained through the mirrored ATT&CK source bundle and object hash. The raw endpoint returns the exact object from the mirrored bundle when available.

Source and licensing

Source: MITRE ATT&CK®. © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation. MITRE ATT&CK and ATT&CK are registered trademarks of The MITRE Corporation. Glexia is not affiliated with or endorsed by MITRE.