Vendor
high
advisory
Unusual Child Process Execution by Web Servers on Linux
2 rules 5 TTPs 13 IOCsThis detection rule identifies suspicious child process executions originating from web server processes on Linux systems, indicating that attackers may have exploited web application vulnerabilities such as command injection or remote file inclusion to establish persistence or execute malicious commands.
Elastic Defend +45
persistence
execution
command-and-control
initial-access
linux
webserver
webshell
privilege-escalation
+4
2r
5t
13i
updated
high
advisory
Unusual Command Execution via Linux Web Server Processes
1 rule 4 TTPsThis brief details how attackers exploit vulnerable web applications or deploy webshells on Linux systems to achieve persistence by executing unusual shell commands from web server processes, potentially leading to payload downloads, reverse shells, or cron-like task implants.
Apache HTTP Server +40
linux-threat
persistence
web-exploitation
webshell
command-execution
detection-rule
elastic-security
1r
4t