CPE
low
advisory
PHP File Creation in WordPress Plugin Directory
1 rule 3 TTPs 1 CVE 1 IOCAttackers commonly establish persistence on compromised Linux WordPress web servers by creating malicious PHP files, often web shells, within the WordPress plugin directory, enabling remote access and command execution following initial compromise of a public-facing application.
WordPress
persistence
initial-access
execution
web-shell
linux
endpoint
threat-detection
vulnerability
1r
3t
1c
1i
updated
low
advisory
Webshell Reconnaissance Command Detection
1 rule 10 TTPs 1 CVEThis brief describes detection of common reconnaissance commands executed through webshells on Windows systems, enabling defenders to identify post-exploitation discovery activities.
webshell
discovery
reconnaissance
attack.persistence
attack.discovery
attack.t1505.003
attack.t1018
attack.t1033
+1
1r
10t
1c