Sponsor of the Day:
Jerkmate
https://detection.fyi/sigmahq/sigma/windows/process_creation/proc_creation_win_webshell_chopper/
Chopper Webshell Process Pattern | Detection.FYI
Detects patterns found in process executions cause by China Chopper like tiny (ASPX) webshells
pattern detection fyichopperwebshellprocess
https://www.fortiguard.com/updates/webshell
Fuzzy Webshell DB for FortiWeb | FortiGuard Labs
fortiguard labsfuzzywebshelldbfortiweb
https://unhosted.org/adventures/6/Controlling-your-server-over-a-WebSocket.html
unhosted web apps 6: webshell
weekly handbook about unhosted web apps
unhosted web apps6webshell
https://threats.wiz.io/all-tools/spinstall0-webshell
spinstall0 webshell
webshell
https://detection.fyi/sigmahq/sigma/emerging-threats/2025/exploits/cve-2025-31324/file_event_win_sap_netweaver_webshell_creation/
Potential SAP NetWeaver Webshell Creation | Detection.FYI
Detects the creation of suspicious files (jsp, java, class) in SAP NetWeaver directories, which may indicate exploitation attempts of vulnerabilities such as …
creation detection fyisap netweaverpotentialwebshell
https://balashoff.ru/
Janus Team - Webshell
janusteamwebshell
https://detection.fyi/sigmahq/sigma/emerging-threats/2021/ta/unc2546/web_unc2546_dewmode_php_webshell/
DEWMODE Webshell Access | Detection.FYI
Detects access to DEWMODE webshell as described in FIREEYE report
access detection fyiwebshell
https://www.f5.com/labs/articles/azure-hosted-scanning-cluster-launches-wordpress-webshell-discovery-campaign
Azure-Hosted Scanning Cluster Launches WordPress Webshell Discovery Campaign | F5 Labs
Sensor Intel Series: March 2026 CVE Trends
cluster launchesf5 labsazurehostedscanning
https://www.wsoshell.org/blog/category/ophellia-webshell/
Ophellia Webshell
webshell
https://detection.fyi/sigmahq/sigma/emerging-threats/2025/exploits/cve-2025-31324/file_event_lnx_sap_netweaver_webshell_creation/
Potential SAP NetWeaver Webshell Creation - Linux | Detection.FYI
Detects the creation of suspicious files (jsp, java, class) in SAP NetWeaver directories, which may indicate exploitation attempts of vulnerabilities such as …
linux detection fyisap netweaverpotentialwebshellcreation