ALT-2408 · Web Server
Web shell uploaded to public web server
A .aspx file was written to /wwwroot/uploads and immediately requested with a cmd parameter.
highNewconfidence 84% · 1969-12-31 18:58:00Z · rule DET-0221 Web Directory Script Write
Detection summary
A .aspx file was written to /wwwroot/uploads and immediately requested with a cmd parameter.
- Affected host
- SRV-WEB-02
- Affected user
- r.wijaya
- Source IP
- 10.20.35.47
- Detection rule
- DET-0221 Web Directory Script Write
- Log source
- Web Server
- Assignee
- A. Pratama
Recommended actions
- Quarantine the file
- Snapshot the server
- Review all upload endpoints
Analyst decision
Triage checklist
- 1. Confirm the detection logic matched genuine activity.
- 2. Check user and asset context for expected behaviour.
- 3. Pivot on host, user, IP and hash in the Log Explorer.
- 4. Enrich IOCs with threat intelligence.
- 5. Set a verdict and record your reasoning.