logo

Advanced Web Shell Detection and Prevention: A Deep Dive into CrowdStrike's Linux Sensor Capabilities

ID: 3895f9d4-1596-50c5-9361-d38c7f5be7b9

STIX ID: report--3895f9d4-1596-50c5-9361-d38c7f5be7b9

Feed Name: Crowdstrike Blog

Threat Score
65/100

Date Published: 2026-02-05

Date Updated: 2026-04-27

Author: Falcon Adversary OverWatch

...
...

This excerpt demonstrates using Falcon LogScale queries to investigate a PHP web shell: it shows a NewScriptWritten event for /var/www/html/uploads/cache.php written by an apache2 process, ScriptControlDetectInfo containing the obfuscated eval payload, PhpExecuteScript confirming execution of the file, and PhpEvalString providing the decoded eval content that reveals the web shell's logic and authentication checks—giving analysts immediate visibility into the malicious script and its execution context.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.