All playbooks
Incident scenarios · Incident responders and SOC leads
Internet-facing server compromise
An edge application exploited, a web shell dropped, and the server used as a foothold inward.
The exploit itself is usually invisible in your logs. What the server does next is not — and that is where every useful answer is.
What this does not establish
- Which vulnerability was used. That comes from the server, not the alert.
- Whether they are still in. A web shell is one door among several.
- Whether this server was the target or the way in.
0 of 10 ticked
Selected step
DetectStep 1 of 10
Identify what the web process spawned or wrote
- A web worker spawning a shell is the signal; the exploit rarely is.
- Look for script files written into web-serving directories.
- Start the timeline now: every action, who took it, when.