Skip to content

Siemphony is in beta and still being built. How a rule earns its badge.

All playbooks

Incident scenarios · Incident responders and SOC leads

Internet-facing server compromise

An edge application exploited, a web shell dropped, and the server used as a foothold inward.

The exploit itself is usually invisible in your logs. What the server does next is not — and that is where every useful answer is.

What this does not establish

  • Which vulnerability was used. That comes from the server, not the alert.
  • Whether they are still in. A web shell is one door among several.
  • Whether this server was the target or the way in.

0 of 10 ticked

Selected step

DetectStep 1 of 10

Identify what the web process spawned or wrote

  • A web worker spawning a shell is the signal; the exploit rarely is.
  • Look for script files written into web-serving directories.
  • Start the timeline now: every action, who took it, when.