From webshell weak signals to meaningful alert in four steps
ID: bb04a504-dd35-53f8-9b29-98c72cb2b127
STIX ID: report--bb04a504-dd35-53f8-9b29-98c72cb2b127
Feed Name: Expel Blog
Threat Score
This post explains a practical method to detect webshell activity by correlating weak network signals (Palo Alto "Vulnerability" alerts) with endpoint indicators (script/file modifications in web-accessible directories). It covers webshell basics, limitations of network-only alerts, and demonstrates how to combine SIEM, firewall alerts, and EDR watchlists (e.g., Carbon Black) to create higher-fidelity, actionable detections.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
