Skip to main content
Splunk Lantern

Deleting web shells automatically

Scenario: A web shell is a malicious interface that enables remote access and control to a web server by allowing the execution of arbitrary commands. A web shell can be uploaded to a web server to enable remote access to the web server. You know that certain attacks, such as those perpetrated by the HAFNIUM group, use web shells. You would like an automated way to remove any web shells created during exploitation so that you don't forget about them.

Prerequisites

To succeed in implementing this use case, you need the following dependencies, resources, and information.

How to use Splunk software for this use case

This playbook formats a block containing a “more” command that extracts the contents of the .aspx file, which contains the webshell. This combines the “more” command with the webshell file path picked up in the event. Next, it runs the more command against the Exchange Server picked up in the event. Then it formats a delete command, and appends the file path from the event. Finally, it runs the delete command on the Exchange server. To use the playbook:

  1. Run the Detect Exchange Web Shell detection in the HAFNIUM Group analytic story in Splunk Enterprise Security.
  2. Enable the Send to Phantom Adaptive Response Action in the Enterprise Security correlation search. After a web shell is written, the detection sends the event to Splunk Phantom .
  3. If you haven't previously used this playbook, configure and activate it.
    1. Navigate to Home>Playbooks and search for delete_detected_files. If it’s not there, click Update from Source Control and select Community to download new community playbooks.
    2. Click the playbook name to open it.
    3. Resolve the playbook import wizard and set the playbook to Active.
    4. Save the playbook and then run it.

Results

If you haven't patched your Exchange servers, the attackers can return and create more webshells. You should patch your servers, but in addition, you can set the playbook to automatically trigger whenever new webshells are detected to delete them as soon as they come in.

Additional resources

These additional Splunk resources might help you understand and implement this use case:

  • Was this article helpful?