logo

From webshell weak signals to meaningful alert in four steps

ID: bb04a504-dd35-53f8-9b29-98c72cb2b127

STIX ID: report--bb04a504-dd35-53f8-9b29-98c72cb2b127

Feed Name: Expel Blog

Threat Score
20/100

Date Published: 2017-09-19

Date Updated: 2026-04-27

Author: Ben Brigida

...
...

This post explains a practical method to detect webshell activity by correlating weak network signals (Palo Alto "Vulnerability" alerts) with endpoint indicators (script/file modifications in web-accessible directories). It covers webshell basics, limitations of network-only alerts, and demonstrates how to combine SIEM, firewall alerts, and EDR watchlists (e.g., Carbon Black) to create higher-fidelity, actionable detections.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.