Product
high
advisory
Unusual Child Process Execution by Web Servers on Linux
2 rules 5 TTPs 13 IOCsThis detection rule identifies suspicious child process executions originating from web server processes on Linux systems, indicating that attackers may have exploited web application vulnerabilities such as command injection or remote file inclusion to establish persistence or execute malicious commands.
Elastic Defend +45
persistence
execution
command-and-control
initial-access
linux
webserver
webshell
privilege-escalation
+4
2r
5t
13i
updated
medium
advisory
Suspicious Command Execution via Linux Web Server
1 rule 14 TTPsThis brief describes how attackers exploit vulnerabilities in web applications to execute suspicious shell commands via web server processes on Linux, enabling persistence, discovery, credential access, and reverse shell establishment, which can lead to full system compromise and data exfiltration.
Apache HTTP Server +45
webserver
command-injection
web-shell
vulnerability-exploitation
persistence
linux
1r
14t