Skip to main contentSkip to main content
Room Banner
Back to all walkthroughs
Room Icon

Detecting Web Shells

Premium room

Explore web shell detection by analyzing logs, file systems, and network traffic.

easy

60 min

14,369

User profile photo.
User profile photo.
User profile photo.

To access material, start machines and answer questions login.

Knowing how to detect web shells is an essential skill for Analysts and Incident Responders. Web shells are a common technique attackers use to gain an initial foothold on target systems. They provide remote access, enabling various actions later in the attack chain. In this room, we will begin by refreshing our understanding of web shells, then dive into detection techniques using a variety of logs and tools.

Learning Objectives

  • Understand what web shells are and how attackers use them
  • Detect web shell activity through log, , and network analysis
  • Understand common tooling in web shell detection

Room Prerequisites

A basic understanding of the topics below will be helpful during this walkthrough.

Answer the questions below

I understand the learning objectives and am ready to embark on a web shell adventure.