Best Detection of 2026 Series: Public-Facing App Exploit to Web Shell
Detects a suspicious sequence of events where a known web server process (e.g., IIS, Nginx, Apache) spawns a command shell process, followed shortly by the creation of a file with a web shell-like extension (.aspx, .jsp, .php) in the same environment. This pattern is indicative of an adversary exploiting a public-facing application to upload and potentially access a web shell.
Microsoft Sentinel (KQL)

