Suspicious Command Execution via Web Server

Identifies suspicious command executions via a web server, which may suggest a vulnerability and remote shell access. Attackers may exploit a vulnerability in a web application to execute commands via a web server, or place a backdoor file that can be abused to gain code execution as a mechanism for persistence.

Elastic rule (View on GitHub)

  1[metadata]
  2creation_date = "2026/06/01"
  3integration = ["endpoint"]
  4maturity = "production"
  5updated_date = "2026/09/18"
  6
  7[rule]
  8author = ["Elastic"]
  9description = """
 10Identifies suspicious command executions via a web server, which may suggest a vulnerability and remote shell access.
 11Attackers may exploit a vulnerability in a web application to execute commands via a web server, or place a backdoor
 12file that can be abused to gain code execution as a mechanism for persistence.
 13"""
 14false_positives = [
 15    """
 16    Network monitoring or management products may have a web server component that runs shell commands as part of normal
 17    behavior.
 18    """,
 19]
 20from = "now-9m"
 21index = ["logs-endpoint.events.process*"]
 22language = "eql"
 23license = "Elastic License v2"
 24name = "Suspicious Command Execution via Web Server"
 25note = """ ## Triage and analysis
 26
 27> **Disclaimer**:
 28> This investigation guide was created using generative AI technology and has been reviewed to improve its accuracy and relevance. While every effort has been made to ensure its quality, we recommend validating the content and adapting it to suit your specific environment and operational needs.
 29
 30### Investigating Suspicious Command Execution via Web Server
 31
 32This alert fires when a Linux web server launches a shell to run commands that look like exploitation activity, such as discovery, credential access, payload decoding, or reverse shell setup. That matters because web servers rarely need to spawn shell commands, so this behavior often signals command injection, a dropped web shell, or attacker persistence. A common pattern is an app exploit causing php-fpm or nginx to run `sh -c 'id; cat /etc/passwd; curl ... | bash'` from `/tmp`.
 33
 34### Possible investigation steps
 35
 36- Review the full process ancestry and execution context to determine what application component invoked the shell, which service account ran it, what working directory and environment it used, and whether the command aligns with any documented application behavior.
 37- Correlate the execution time with web server access, error, and application logs to identify the triggering request, including source IP, requested URI, parameters, headers, authenticated user or session, and any indications of command injection or direct web shell access.
 38- Inspect recently created or modified files in the web root and writable locations such as upload, cache, temp, and shared-memory directories for dropped scripts, encoded payloads, cron changes, SSH key additions, or other persistence artifacts tied to the command.
 39- Scope for follow-on activity by pivoting on the source IP, command fragments, spawned children, outbound connections, and similar executions on other web servers to determine whether exploitation was successful, repeated, or part of a broader campaign.
 40- If the activity is unauthorized or cannot be explained, isolate the host, preserve relevant volatile and disk evidence, rotate secrets accessible to the web service, and remediate the vulnerable application or remove any discovered web shell before restoring service.
 41
 42### False positive analysis
 43
 44- A legitimate web administration or diagnostics function may invoke `sh -c` to run commands such as `id`, `whoami`, `hostname`, or read OS metadata for status pages; verify the command matches documented application behavior and correlate it to an authorized request in web or application logs.
 45- A normal application workflow may use the web server to unpack user uploads or stage temporary content under `/tmp`, `/var/tmp`, or `/dev/shm` during import, conversion, or update operations; verify the execution aligns with a known user action or scheduled maintenance window and that the created files are expected temporary artifacts owned by the service account.
 46
 47### Response and remediation
 48
 49- Isolate the affected web server from the network or remove it from the load balancer immediately, preserve a forensic snapshot if possible, and block the attacker-controlled IPs, domains, and downloaded payload locations observed in the command chain.
 50- Hunt for and remove persistence by deleting web shells and dropped scripts in the document root, uploads, `/tmp`, `/var/tmp`, and `/dev/shm`, and by cleaning unauthorized cron entries, systemd services, startup scripts, SSH `authorized_keys`, and any attacker-created local accounts.
 51- Reset trust on the host by rotating application secrets, database passwords, API tokens, cloud credentials, and SSH keys that were present or reachable from the web server, and invalidate active sessions tied to the compromised application.
 52- Rebuild or reimage the server from a known-good source, patch the exploited web application or server component, restore only validated content and configurations, and verify no unauthorized binaries, modified packages, or backdoored application files remain before returning it to service.
 53- Escalate to incident response immediately if the shell command opened a reverse shell, downloaded or piped a payload into an interpreter, accessed sensitive files such as `/etc/shadow`, `.ssh`, or cloud credential stores, or if similar activity is found on additional hosts.
 54- Harden the environment by removing unnecessary shell execution from the application, disabling write and execute permissions in web-accessible upload and temp paths, enforcing least privilege for the web service account, enabling WAF or virtual patching for the exploited weakness, and increasing monitoring on web roots and startup locations.
 55"""
 56risk_score = 47
 57rule_id = "6148b9f5-5b12-4704-9ef7-f4b4c5dd9bb5"
 58setup = """## Setup
 59
 60This rule requires data coming in from Elastic Defend.
 61
 62### Elastic Defend Integration Setup
 63Elastic Defend is integrated into the Elastic Agent using Fleet. Upon configuration, the integration allows the Elastic Agent to monitor events on your host and send data to the Elastic Security app.
 64
 65#### Prerequisite Requirements:
 66- Fleet is required for Elastic Defend.
 67- To configure Fleet Server refer to the [documentation](https://www.elastic.co/guide/en/fleet/current/fleet-server.html).
 68
 69#### The following steps should be executed in order to add the Elastic Defend integration on a Linux System:
 70- Go to the Kibana home page and click "Add integrations".
 71- In the query bar, search for "Elastic Defend" and select the integration to see more details about it.
 72- Click "Add Elastic Defend".
 73- Configure the integration name and optionally add a description.
 74- Select the type of environment you want to protect, either "Traditional Endpoints" or "Cloud Workloads".
 75- Select a configuration preset. Each preset comes with different default settings for Elastic Agent, you can further customize these later by configuring the Elastic Defend integration policy. [Helper guide](https://www.elastic.co/guide/en/security/current/configure-endpoint-integration-policy.html).
 76- We suggest selecting "Complete EDR (Endpoint Detection and Response)" as a configuration setting, that provides "All events; all preventions"
 77- Enter a name for the agent policy in "New agent policy name". If other agent policies already exist, you can click the "Existing hosts" tab and select an existing policy instead.
 78For more details on Elastic Agent configuration settings, refer to the [helper guide](https://www.elastic.co/guide/en/fleet/8.10/agent-policy.html).
 79- Click "Save and Continue".
 80- To complete the integration, select "Add Elastic Agent to your hosts" and continue to the next section to install the Elastic Agent on your hosts.
 81For more details on Elastic Defend refer to the [helper guide](https://www.elastic.co/guide/en/security/current/install-endpoint.html).
 82"""
 83severity = "medium"
 84tags = [
 85    "Domain: Endpoint",
 86    "OS: Linux",
 87    "Use Case: Threat Detection",
 88    "Tactic: Persistence",
 89    "Tactic: Initial Access",
 90    "Use Case: Vulnerability",
 91    "Data Source: Elastic Defend",
 92    "Resources: Investigation Guide",
 93    "Noise: High",
 94    "Performance: Normal",
 95    "Profile: Aggressive",
 96    "Threat: Web Shell",
 97    "Rule Type: Event Correlation (EQL)",
 98    "Platform: Linux",
 99]
100timestamp_override = "event.ingested"
101type = "eql"
102query = '''
103process where host.os.type == "linux" and event.type == "start" and event.action == "exec" and (
104  process.parent.name in (
105    "nginx", "apache2", "httpd", "caddy", "mongrel_rails", "uwsgi", "daphne", "httpd.worker", "flask",
106    "php-cgi", "php-fcgi", "php-cgi.cagefs", "lswsctrl", "varnishd", "uvicorn", "waitress-serve", "starman",
107    "frankenphp", "zabbix_server", "asterisk", "sw-engine-fpm"
108  ) or
109  process.parent.name like ("php-fpm*", "lsphp*", "gunicorn*", "*.cgi", "*.fcgi") or
110  (
111    process.parent.name like "ruby*" and
112    process.parent.command_line like~ ("*puma*", "*rails*", "*passenger*")
113  ) or
114  (
115    process.parent.name like "python*" and
116    process.parent.command_line like~ (
117      "*hypercorn*", "*flask*", "*uvicorn*", "*django*", "*app.py*", "*server.py*", "*wsgi.py*", "*asgi.py*"
118    )
119  ) or
120  (process.parent.name like "perl*" and process.parent.command_line like~ "*plackup*") or
121  (
122    process.parent.name == "java" and (
123      process.parent.args like~ (
124        /* Tomcat */
125        "org.apache.catalina.startup.Bootstrap", "-Dcatalina.base=*",
126
127        /* Jetty */
128        "org.eclipse.jetty.start.Main", "-Djetty.home=*",
129
130        /* WildFly / JBoss */
131        "org.jboss.modules.Main", "-Djboss.home.dir=*",
132
133        /* WebLogic */
134        "weblogic.Server", "-Dweblogic.Name=*", "*weblogic-launcher.jar*",
135
136        /* WebSphere traditional + Liberty */
137        "com.ibm.ws.runtime.WsServer", "com.ibm.ws.kernel.boot.cmdline.Bootstrap",
138
139        /* GlassFish */
140        "com.sun.enterprise.glassfish.bootstrap.ASMain",
141
142        /* Resin */
143        "com.caucho.server.resin.Resin",
144
145        /* Spring Boot */
146        "org.springframework.boot.loader.*",
147
148        /* Quarkus */
149        "*quarkus-run.jar*", "io.quarkus.runner.GeneratedMain",
150
151        /* Micronaut */
152        "io.micronaut.runtime.Micronaut",
153
154        /* Dropwizard */
155        "io.dropwizard.cli.ServerCommand",
156
157        /* Play */
158        "play.core.server.ProdServerStart",
159
160        /* Helidon */
161        "io.helidon.microprofile.server.Main", "io.helidon.webserver*",
162
163        /* Vert.x */
164        "io.vertx.core.Launcher",
165
166        /* Keycloak */
167        "org.keycloak*",
168
169        /* Apereo CAS */
170        "org.apereo.cas*",
171
172        /* Elasticsearch */
173        "org.elasticsearch.bootstrap.Elasticsearch",
174
175        /* Atlassian / Gerrit */
176        "com.atlassian.jira.startup.Launcher", "*BitbucketServerLauncher*", "com.google.gerrit.pgm.Daemon",
177
178        /* Solr */
179        "*-Dsolr.solr.home=*",
180
181        /* Jenkins */
182        "*jenkins.war*"
183      ) or
184      ?process.working_directory like "/u0?/*"
185    )
186  )
187) and
188process.name in ("bash", "dash", "sh", "tcsh", "csh", "zsh", "ksh", "fish", "mksh", "busybox") and
189process.args in ("-c", "-cl", "-lc") and (
190  process.command_line like~ (
191
192    /* Suspicious Paths */
193    "* /tmp/* ", "* /var/tmp/* ", "* /dev/shm/*", "* /run/*", "* /var/run/*",
194
195    /* Encoding, Decoding & Piping */
196    "*|sh", "*| sh *", "*| sh ", "*|bash*", "*| bash*", "*|zsh*",  "*| zsh*", "*|dash*",  "*| dash*",
197    "*|python*", "*| python*", "*|php*", "*| php*", "*|perl*", "*| perl*", "*|ruby*", "*| ruby*",
198    "*|node*", "*| node*", "*|lua*",  "*| lua*", "*|busybox*", "*| busybox*", "*|*base64 -d*", "*|*base64 --decode*",
199    "*|*base64 --decode*", "*|*openssl base64 -d*", "*xxd *", "*| openssl*enc * -d *", "*b64decode -r*",
200
201    /* Interpreter Execution */
202    "*python -c*", "*python3 -c*", "*php -r*", "*perl -e*", "*ruby -e*", "*lua -e*", "*node -e *",
203
204    /* Reverse Shells */
205    "*netcat *", "* nc *", "*ncat *", "*/dev/tcp*", "*/dev/udp/*", "*socat *", "*openssl*s_client *", "*stty*raw*-echo*",
206    "*mkfifo /tmp/*", 
207
208    /* File Access */
209    "*>*/etc/cron*", "*crontab*", "*/etc/ssh*", "*/home/*/.ssh/*", "*/root/.ssh*", "*~/.ssh/*", "*/etc/shadow*",
210    "*/etc/passwd*", "*/etc/master.passwd*",
211
212    /* Enumeration & Discovery */
213    "*/etc/hosts*", "*/etc/resolv.conf*", "*/etc/hostname*", "*/etc/issue*", "*/etc/os-release*", "*lsb_release*",
214    "*/proc/*/environ*", "*sudo -l*", "*/proc/*/cgroup*", "*dockerenv*", "*/proc/*/mountinfo*", "*printenv*",
215    "*cat*.env *", "*getcap*", "*capsh*", "*find / *", "*netstat *",
216
217    /* AWS Credentials */
218    "*aws_access_key_id*", "*aws_secret_access_key*", "*aws_session_token*", "*accesskeyid*", "*secretaccesskey*",
219    "*.aws/credentials*", "*/.aws/config*",
220
221    /* Azure Credentials */
222    "*AZURE_CLIENT_ID*", "*AZURE_TENANT_ID*", "*AZURE_CLIENT_SECRET*", "*AZURE_FEDERATED_TOKEN_FILE*",
223    "*IDENTITY_ENDPOINT*", "*IDENTITY_HEADER*", "*MSI_ENDPOINT*", "*MSI_SECRET*", "*/.azure/*",
224    "*/run/secrets/azure/*",
225
226    /* GCP Credentials */
227    "*/.config/gcloud/*", "*application_default_credentials.json*", "*type: service_account*",
228    "*client_email*", "*private_key_id*", "*/run/secrets/google/*", "*GOOGLE_APPLICATION_CREDENTIALS*",
229
230    /* Misc. Cloud */
231    "*/.docker/config.json*", "*/.npmrc*", "*/secrets/kubernetes.io/serviceaccount/*",
232
233    /* Helpers */
234    "*timeout *sh -c *", "*env *sh *-c*", "*exec -a*",
235
236    /* Miscellaneous */
237    "*chattr *", "*busybox *",  "*#!*", "*chmod +x *", "*chmod 777*", "*chpasswd*",
238    "*<?php*?>*", "*kworker*",
239    
240    /* Decompression */
241    "*gzip -*d *", "*bzip2 -*d *", "*xz -*d *", "*tar -*x*",
242    
243    /* Path Traversal */
244    "*../../../*etc/*", "*/.../*", "*../../../*home/*/*", "*../../../*root/*",
245
246    /* File Upload/Download */
247    "*pastebin.com*", "*transfer.sh*", "*bashupload.com*",
248
249    /* Enumeration & Discovery */
250    "* id *", "* whoami *", "* hostname *"
251  ) or
252  /* Keep this to not miss FNs due to spacing */
253  process.args in ("id", "whoami", "hostname")
254) and
255not (
256  (
257    process.parent.name == "nginx" and
258    process.args like ("chmod 777 /etc/resty-*", "resty*")
259  ) or
260  (
261    process.parent.name == "apache2" and (
262      process.command_line in (
263        "sh -c /usr/local/bin/php -r 'echo phpversion();'", "sh -c -- /usr/local/bin/php -r 'echo phpversion();'",
264        "sh -c /usr/bin/php -r 'echo phpversion();'",
265        "sh -c /usr/bin/lsb_release -a 2>/dev/null"
266      ) or
267      process.args like (
268        """bash -c "( /home/*/apps/richdocumentscode/collabora/Collabora_Online.AppImage*""",
269        "chmod 777 /etc/cobra/uploads/mysql*", "stat*"
270      ) or
271      process.command_line like (
272        "*/usr/bin/crontab*phpupdatecrontab.txt", "*mysqldump*/var/www/html/*/writable/uploads/backup/mysql*",
273        "sh -c chmod 777 -R /opt/data/www/php_upload/*/temp"
274      )
275    )
276  ) or
277  (
278    process.parent.name like "php-fpm*" and (
279      process.command_line in (
280        "sh -c /usr/bin/php -r 'echo phpversion();'", "sh -c -- /usr/bin/php -r 'echo phpversion();'",
281        "sh -c php -r 'print_r(phpversion());'", "sh -c chattr -i -a /usr/local/virtualizor/license2.php",
282        "sh -c source /etc/os-release 2>/dev/null && echo $ID $ID_LIKE",
283        "sh -c php -r \"echo date('T');\"",
284        "sh -c php -r \"echo PHP_VERSION;\""
285      ) or
286      process.command_line like (
287        "*var_export*extension_loaded*", "*/tmp/tmp_resize*", "*/v1/objects/hosts/*_Infoterminal*", "*python -m json.tool*",
288        "sh -c timeout 3600 ssh -o ControlMaster=auto -o ControlPath=/var/www/html/storage/app/ssh/mux/*"
289      ) or
290      process.args like ("ps*|*grep*", "ffmpeg*")
291    )
292  ) or
293  (
294    process.parent.name == "php-cgi" and (
295      process.command_line like (
296        "sh -c nohup php /home/*/public_html/lockindex.php index.php >/dev/null 2>&1 &",
297        "sh -c nohup php /home/*/public_html/wp-content/* >> /dev/null 2>&1 &",
298        "sh -c nohup php /home/*/public_html/wp-includes/* >> /dev/null 2>&1 &",
299        "sh -c nohup php /home/*/public_html/*/wp-content/* >> /dev/null 2>&1 &",
300        "*-ef|grep*"
301      ) or
302      process.args like "ps*| grep*"
303    )
304  ) or
305  (
306    process.command_line == "/bin/sh -c echo | openssl s_client -connect localhost:61617 2>/dev/null | openssl x509 -noout -enddate" and
307    process.parent.name == "gunicorn"
308  ) or
309  (
310    process.parent.executable == "/usr/local/bin/gunicorn" and
311    process.command_line == "/bin/sh -c echo 'Q' | openssl s_client -connect localhost:61617 2>/dev/null | openssl x509 -noout -enddate"
312  ) or
313  (
314   process.parent.executable == "/opt/bitnami/apache/bin/httpd" and
315   process.command_line == "sh -c /opt/bitnami/php/bin/php -r 'echo phpversion();'"
316  ) or
317  (
318    process.parent.executable like "/var/lib/containers/storage/overlay/*/merged/usr/local/sbin/php-fpm" and
319    process.command_line == "sh -c /usr/local/bin/php -r 'echo phpversion();'"
320  ) or
321  (
322    process.parent.executable like "/var/lib/docker/overlay2/*/merged/usr/sbin/uwsgi" and
323    process.command_line == "/bin/sh -c { touch /run/uwsgi-logrotate  }"
324  ) or
325  (process.parent.name like "python*" and process.parent.command_line like "*hive_server.py*") or
326  (process.parent.name == "sw-engine-fpm" and process.command_line like ("*/opt/psa/admin/bin/*", "*/usr/local/psa/admin/*")) or
327  (process.parent.name == "httpd" and process.command_line like ("*/datastore/htdocs/control-states/compass*", "*/dev/shm/netmon-log*")) or
328  (process.parent.name == "asterisk" and process.args like "/bin/chmod 777 */gravacoes/*.WAV") or
329  (process.parent.name == "nginx" and process.command_line like "sh -c gcc -print-multiarch 2>/dev/null > /tmp/lua_*") or
330  (process.parent.name == "varnishd" and process.args like "exec gcc*") or
331  (process.parent.name == "zabbix_server" and process.command_line like "*/usr/sbin/sendmail*") or
332  (process.parent.executable == "/opt/morpheus/embedded/java/jre/bin/java" and process.command_line like "*morpheus-local*") or
333  (
334    process.parent.name == "ruby" and
335    process.command_line in (
336      "sh -c echo \"^d\" | openssl s_client -connect 127.0.0.1:443 2>&1",
337      "sh -c cat /etc/hosts.allow 2>/dev/null"
338    )
339  ) or
340  (process.parent.name == "java" and process.args like "chmod 777 *.csv") or
341  process.command_line == "sh -c node -v || nodejs -v" or
342  process.working_directory like ("/var/lib/puppet/rack/puppetmasterd", "/u01/app/*/sysman/emd")
343)
344'''
345
346[[rule.threat]]
347framework = "MITRE ATT&CK"
348
349[[rule.threat.technique]]
350id = "T1505"
351name = "Server Software Component"
352reference = "https://attack.mitre.org/techniques/T1505/"
353
354[[rule.threat.technique.subtechnique]]
355id = "T1505.003"
356name = "Web Shell"
357reference = "https://attack.mitre.org/techniques/T1505/003/"
358
359[rule.threat.tactic]
360id = "TA0003"
361name = "Persistence"
362reference = "https://attack.mitre.org/tactics/TA0003/"
363
364[[rule.threat]]
365framework = "MITRE ATT&CK"
366
367[[rule.threat.technique]]
368id = "T1190"
369name = "Exploit Public-Facing Application"
370reference = "https://attack.mitre.org/techniques/T1190/"
371
372[rule.threat.tactic]
373id = "TA0001"
374name = "Initial Access"
375reference = "https://attack.mitre.org/tactics/TA0001/"
376
377[[rule.threat]]
378framework = "MITRE ATT&CK"
379
380[[rule.threat.technique]]
381id = "T1059"
382name = "Command and Scripting Interpreter"
383reference = "https://attack.mitre.org/techniques/T1059/"
384
385[rule.threat.tactic]
386id = "TA0002"
387name = "Execution"
388reference = "https://attack.mitre.org/tactics/TA0002/"

Triage and analysis

Disclaimer: This investigation guide was created using generative AI technology and has been reviewed to improve its accuracy and relevance. While every effort has been made to ensure its quality, we recommend validating the content and adapting it to suit your specific environment and operational needs.

Investigating Suspicious Command Execution via Web Server

This alert fires when a Linux web server launches a shell to run commands that look like exploitation activity, such as discovery, credential access, payload decoding, or reverse shell setup. That matters because web servers rarely need to spawn shell commands, so this behavior often signals command injection, a dropped web shell, or attacker persistence. A common pattern is an app exploit causing php-fpm or nginx to run sh -c 'id; cat /etc/passwd; curl ... | bash' from /tmp.

Possible investigation steps

  • Review the full process ancestry and execution context to determine what application component invoked the shell, which service account ran it, what working directory and environment it used, and whether the command aligns with any documented application behavior.
  • Correlate the execution time with web server access, error, and application logs to identify the triggering request, including source IP, requested URI, parameters, headers, authenticated user or session, and any indications of command injection or direct web shell access.
  • Inspect recently created or modified files in the web root and writable locations such as upload, cache, temp, and shared-memory directories for dropped scripts, encoded payloads, cron changes, SSH key additions, or other persistence artifacts tied to the command.
  • Scope for follow-on activity by pivoting on the source IP, command fragments, spawned children, outbound connections, and similar executions on other web servers to determine whether exploitation was successful, repeated, or part of a broader campaign.
  • If the activity is unauthorized or cannot be explained, isolate the host, preserve relevant volatile and disk evidence, rotate secrets accessible to the web service, and remediate the vulnerable application or remove any discovered web shell before restoring service.

False positive analysis

  • A legitimate web administration or diagnostics function may invoke sh -c to run commands such as id, whoami, hostname, or read OS metadata for status pages; verify the command matches documented application behavior and correlate it to an authorized request in web or application logs.
  • A normal application workflow may use the web server to unpack user uploads or stage temporary content under /tmp, /var/tmp, or /dev/shm during import, conversion, or update operations; verify the execution aligns with a known user action or scheduled maintenance window and that the created files are expected temporary artifacts owned by the service account.

Response and remediation

  • Isolate the affected web server from the network or remove it from the load balancer immediately, preserve a forensic snapshot if possible, and block the attacker-controlled IPs, domains, and downloaded payload locations observed in the command chain.
  • Hunt for and remove persistence by deleting web shells and dropped scripts in the document root, uploads, /tmp, /var/tmp, and /dev/shm, and by cleaning unauthorized cron entries, systemd services, startup scripts, SSH authorized_keys, and any attacker-created local accounts.
  • Reset trust on the host by rotating application secrets, database passwords, API tokens, cloud credentials, and SSH keys that were present or reachable from the web server, and invalidate active sessions tied to the compromised application.
  • Rebuild or reimage the server from a known-good source, patch the exploited web application or server component, restore only validated content and configurations, and verify no unauthorized binaries, modified packages, or backdoored application files remain before returning it to service.
  • Escalate to incident response immediately if the shell command opened a reverse shell, downloaded or piped a payload into an interpreter, accessed sensitive files such as /etc/shadow, .ssh, or cloud credential stores, or if similar activity is found on additional hosts.
  • Harden the environment by removing unnecessary shell execution from the application, disabling write and execute permissions in web-accessible upload and temp paths, enforcing least privilege for the web service account, enabling WAF or virtual patching for the exploited weakness, and increasing monitoring on web roots and startup locations.

Related rules

to-top