T1100 Web Shell is a MITRE ATT&CK technique where an attacker deploys a web-accessible shell on a compromised web server to execute commands, maintain persistence, and pivot within the network.
T1100 - Web Shell is a mitre_attack tracked across 3 threat clusters and 2 intelligence report mentions on ThreatCluster. First observed November 13, 2025; most recent activity December 11, 2025.
T1100 Web Shell is a MITRE ATT&CK technique where an attacker deploys a web-accessible shell on a compromised web server to execute commands, maintain persistence, and pivot within the network. Key traits include lightweight, server-side scripts (e.g., PHP, ASP, JSP) or binaries, covert command and control, and post-exploitation use to remotely control assets. It remains significant due to its effectiveness for long-term access and easy integration into broader intrusion chains.
A critical vulnerability in FortiWeb Web Application Firewall (WAF) has been actively exploited, allowing attackers to gain full administrative access to affected systems. Organizations using FortiWeb are at risk of…
An advanced persistent threat (APT) group exploited zero-day vulnerabilities in Cisco Identity Services Engine (ISE) and Citrix systems, specifically CVE-2025-5777 and CVE-2025-20337. The attacks were detected by…
Two former Cisco Networking Academy trainees, Qiu Daibing and Yu Yang, have been identified as potential orchestrators of the Salt Typhoon cyber espionage campaign that targeted critical networks in 2024. The attackers…
T1100 Web Shell is a MITRE ATT&CK technique where an attacker deploys a web-accessible shell on a compromised web server to execute commands, maintain persistence, and pivot within the network.
The most recent intelligence report mentioning T1100 - Web Shell on ThreatCluster is dated December 11, 2025. Activity was first observed November 13, 2025, giving a tracked span from then to December 11, 2025.
Across ThreatCluster reporting, T1100 - Web Shell most frequently co-occurs with Salt Typhoon, Malware, Zero-day Exploit, Citrix Bleed 2, Australia, among 12 tracked related entities.
The most significant recent cluster is “FortiWeb WAF Vulnerability Enables Full Admin Control Exploitation” (100 articles · Updated November 15, 2025). T1100 - Web Shell appears across 3 threat clusters in total, listed above with sources.
T1100 - Web Shell appears in 2 intelligence report mentions across 3 deduplicated threat clusters, aggregated from 17,000+ monitored sources.