Product
high
advisory
Unusual Command Execution via Linux Web Server Processes
1 rule 4 TTPsThis brief details how attackers exploit vulnerable web applications or deploy webshells on Linux systems to achieve persistence by executing unusual shell commands from web server processes, potentially leading to payload downloads, reverse shells, or cron-like task implants.
Apache HTTP Server +40
linux-threat
persistence
web-exploitation
webshell
command-execution
detection-rule
elastic-security
1r
4t
medium
advisory
Suspicious Command Execution via Linux Web Server
1 rule 14 TTPsThis brief describes how attackers exploit vulnerabilities in web applications to execute suspicious shell commands via web server processes on Linux, enabling persistence, discovery, credential access, and reverse shell establishment, which can lead to full system compromise and data exfiltration.
Apache HTTP Server +45
webserver
command-injection
web-shell
vulnerability-exploitation
persistence
linux
1r
14t