Location Research Breakthrough Possible @S-Logix pro@slogix.in

Detecting Web Shell Deployment Attacks Against Apache HTTP Servers Through Web-Server File Integrity Monitoring and Automated Process Isolation

Description

Modern web applications hosted on Apache HTTP Servers depend on web-server files, application scripts, configuration files, and supporting resources to provide application functionality. If an attacker successfully places a malicious web shell inside a web-accessible directory, the attacker may attempt to execute commands through HTTP requests and maintain unauthorized control over the compromised server.

A web shell is a malicious server-side script or executable component placed on a web server to provide remote command execution or persistent access through web requests. Detecting such deployment requires monitoring changes to web-server directories and correlating suspicious file modifications with process activity.

In this use case, an Apache HTTP Server is deployed as the controlled web-server environment on an Ubuntu virtual machine. The Apache document root and relevant web-server directories are monitored for unexpected file creation and modification.

A controlled web-shell deployment assessment is performed from Kali Linux. A controlled test web-shell file is introduced into the laboratory Apache web directory to validate whether the monitoring mechanism identifies the file modification. Wazuh is used for file integrity monitoring and security-event collection, while OpenSearch is used for security-event analysis.

The security assessment focuses on determining whether a newly deployed or modified web-server file can be detected and correlated with suspicious process activity.

The proposed defensive mechanism implements web-server file integrity monitoring and automated process isolation. File changes within monitored Apache directories generate security events, while suspicious activity can trigger an automated response that isolates the associated process from continued execution.

After implementing the security controls, the web-shell deployment assessment is repeated to verify that the malicious file change is detected and that the corresponding suspicious process activity is contained.

Complete Security Flow: Apache Web Directory → Web Shell File Deployment → File Integrity Change Detected → Security Event Generated → Suspicious Process Activity Correlated → Alert Generated → Automated Process Isolation → Incident Validation

Existing Security Problem

Application: Apache HTTP Server

Apache HTTP Server is used as the controlled web-server environment for testing web-shell deployment and server-side file-integrity security. The Apache document root contains web-accessible files that are processed or served by the web server. If an attacker places a malicious server-side file into a web-accessible directory, the file may potentially be invoked through an HTTP request.

Existing Problem:

Web-shell deployment becomes difficult to detect when changes to Apache web-server directories are not continuously monitored. A newly created or modified server-side file may appear similar to a legitimate application file unless file-integrity monitoring and process-level security monitoring are implemented. The proposed solution introduces file integrity monitoring for Apache web-server directories and correlates file-change events with suspicious process activity so that web-shell deployment can be detected and the associated process can be isolated.

The security problem is therefore:

Apache HTTP Server → Web-Accessible Application Directory → Unexpected Server-Side File Creation → Web Shell Deployment → Web Shell Access Through HTTP Request → Suspicious Server Process Activity → Potential Remote Command Execution → Delayed Detection → Web-Server Security Risk

Implement file integrity monitoring for Apache web-server directories and correlate file-change events with suspicious process activity to detect web-shell deployment and isolate the associated process.

Attack

Specific Attack: Web Shell Deployment

A web shell deployment attack involves placing a malicious server-side script or executable component within a web-accessible server directory. The attacker first identifies a location where a server-side file can be introduced into the Apache web directory. During controlled testing, a benign laboratory web-shell simulation is placed within the monitored Apache document root. The deployed file is then accessed through the controlled HTTP service to generate corresponding web-server and process activity.

The controlled assessment introduces a test file into the monitored Apache directory, accesses it through the laboratory HTTP service, and reviews whether the resulting file-integrity and process activity are detected and correlated.

Attack Behavior:
Apache HTTP Server Identified
→
Web-Accessible Directory Identified
→
Controlled Malicious File Introduced
→
Web Shell File Created
→
Apache Detects or Serves File
→
HTTP Request Sent to Web Shell
→
Server-Side Process Activity Generated
→
File Integrity Event Correlated
→
Suspicious Activity Detected
→
Process Isolation Triggered

Security Concept

Web-Server File Integrity Monitoring:

Critical Apache web-server directories should be continuously monitored for unexpected file creation, modification, deletion, and permission changes.

File integrity monitoring establishes and checks the expected state of important web-server files and directories. By analyzing file-change events alongside relevant process activity, security monitoring can help identify potential web-shell deployment and support a timely response.

The secure processing flow is:

Web Directory Monitoring
→
File Change Detection
→
File Integrity Event
→
Security Analysis
→
Process Correlation
→
Threat Detection
→
Automated Response

Defensive Mechanism

Apache Web Directory Monitoring

Critical Apache document-root directories are configured for continuous file-integrity monitoring.

Purpose

Detect unexpected files introduced into web-accessible directories.

File Creation Detection

New files created within monitored directories generate security events.

Purpose

Identify potential web-shell deployment activity.

File Modification Detection

Changes to existing application and web-server files are monitored.

Purpose

Detect malicious code insertion into legitimate files.

File Integrity Baseline

Expected file states are established for monitored web-server content.

Purpose

Provide a reference for detecting unauthorized changes.

Process Monitoring

Processes associated with web-server activity are monitored for suspicious execution behavior.

Purpose

Identify process activity associated with potential web-shell execution.

File and Process Event Correlation

File-integrity events are correlated with relevant process activity.

Purpose

Connect suspicious file deployment with possible execution behavior.

Automated Process Isolation

The response mechanism isolates or terminates the suspicious process when configured detection conditions are satisfied.

Purpose

Stop continued execution of the detected malicious server-side process.

Security Event Logging

File changes, process activity, detection events, and response actions are recorded.

Purpose

Support incident investigation, response validation, and post-incident analysis.

Security Tools

Wazuh

Wazuh is used to monitor Apache web-server files, collect security events, detect file-integrity changes, and support automated response.

Purpose
  • Monitor Apache document-root directories.
  • Detect file creation.
  • Detect file modification.
  • Generate file-integrity security events.
  • Monitor process activity.
  • Correlate security events.
  • Trigger automated response actions.
  • Validate post-remediation detection.

OpenSearch

OpenSearch is used to analyze and visualize security events generated during the web-shell deployment assessment.

Purpose
  • Analyze file-integrity events.
  • Review process-related events.
  • Correlate timestamps.
  • Investigate detected web-shell activity.
  • Review response events.
  • Support incident investigation.

Apache HTTP Server

Apache HTTP Server provides the controlled web-server environment.

Purpose
  • Host the controlled web application.
  • Provide the monitored web directory.
  • Process HTTP requests.
  • Generate web-server activity.
  • Provide the environment for web-shell deployment testing.

Ubuntu

Ubuntu hosts Apache HTTP Server and the security-monitoring components.

Purpose
  • Run Apache HTTP Server.
  • Host monitored web files.
  • Execute controlled server-side processes.
  • Generate system events.
  • Support Wazuh monitoring.

Kali Linux

Kali Linux is used as the controlled security-testing environment.

Purpose
  • Send controlled HTTP requests.
  • Perform web-server security testing.
  • Validate web-shell deployment detection.
  • Access the controlled Apache service.
  • Verify post-response behavior.

VirtualBox

VirtualBox provides the isolated laboratory environment.

Purpose
  • Create the Ubuntu and Kali virtual machines.
  • Provide controlled network connectivity.
  • Separate the web-server and testing environments.
  • Maintain a reproducible security-testing laboratory.

Process

STEP 01

Step 1: Prepare the Virtualized Cyber Defense Environment

  • Create an isolated cybersecurity laboratory using VirtualBox.
  • Configure Ubuntu as the Apache web-server and security-monitoring environment.
  • Configure Kali Linux as the security-testing environment.
  • Configure the virtual network to allow controlled communication between the virtual machines.
  • Verify connectivity between Kali Linux and Ubuntu.
  • Confirm that Kali Linux can reach the Apache HTTP Server.
  • Ensure that all testing remains inside the controlled laboratory.
Tools: VirtualBox + Ubuntu + Kali Linux
STEP 02

Step 2: Deploy Apache HTTP Server

  • Install and configure Apache HTTP Server on Ubuntu.
  • Start the Apache service.
  • Verify that the web server is running correctly.
  • Identify the Apache document-root directory.
  • Place a controlled legitimate web application file inside the document root.
  • Access the application from Kali Linux.
  • Confirm normal HTTP functionality before security testing.
Tools: Ubuntu + Apache HTTP Server
STEP 03

Step 3: Identify Critical Web-Server Files and Directories

  • Identify the Apache document-root directory.
  • Identify application source files and server-side scripts.
  • Identify Apache configuration files requiring protection.
  • Identify directories where web-accessible files are stored.
  • Determine which directories require file-integrity monitoring.
  • Document the initial file structure.
Tools: Ubuntu + Apache HTTP Server
STEP 04

Step 4: Establish the Web-Server File Integrity Baseline

  • Record the expected files within the monitored Apache directories.
  • Calculate or establish the initial integrity state of monitored files.
  • Verify file ownership and permissions.
  • Confirm that legitimate application files are present.
  • Establish the baseline before introducing controlled changes.
  • Record the baseline state for later comparison.
Tools: Ubuntu + Wazuh
STEP 05

Step 5: Configure Wazuh File Integrity Monitoring

  • Configure Wazuh to monitor the Apache document-root directory.
  • Configure monitoring for file creation and modification events.
  • Configure monitoring for relevant file attributes.
  • Apply the monitoring configuration.
  • Restart or reload the required monitoring components.
  • Verify that Wazuh is receiving file-integrity events.
Tools: Ubuntu + Wazuh
STEP 06

Step 6: Configure Process Monitoring

  • Configure Wazuh monitoring for relevant process activity.
  • Identify Apache-related processes.
  • Establish normal Apache process behavior.
  • Monitor process creation and termination events.
  • Record the normal process state of the Apache service.
  • Prepare process monitoring for correlation with file-integrity events.
Tools: Wazuh + Ubuntu + Apache HTTP Server
STEP 07

Step 7: Establish Normal Web-Server Activity

  • Access legitimate Apache web pages from Kali Linux.
  • Send normal HTTP requests to the application.
  • Observe Apache access behavior.
  • Confirm that legitimate requests do not generate unexpected file-integrity events.
  • Confirm that Apache processes remain in their expected state.
  • Record the normal security-monitoring baseline.
Tools: Kali Linux + Apache HTTP Server + Wazuh
STEP 08

Step 8: Identify the Web Shell Deployment Attack Surface

  • Identify a controlled web-accessible directory.
  • Determine where a server-side file could potentially be introduced.
  • Identify the HTTP endpoint through which the file would be accessed.
  • Determine the expected server-side processing behavior.
  • Document the controlled web-shell deployment path.
  • Ensure that only laboratory files are used during testing.
Tools: Kali Linux + Apache HTTP Server + Ubuntu
STEP 09

Step 9: Perform Controlled Web Shell File Deployment

  • Create a controlled laboratory web-shell simulation file.
  • Place the file inside the monitored Apache web directory.
  • Observe the resulting file-integrity event.
  • Verify whether Wazuh detects the newly created file.
  • Record the affected file path and event timestamp.
  • Do not deploy the test file to external or production systems.
Tools: Kali Linux + Ubuntu + Wazuh
STEP 10

Step 10: Generate Controlled Web Shell Access Activity

  • Send a controlled HTTP request to the laboratory web-shell simulation.
  • Observe the Apache access event.
  • Monitor the corresponding server-side activity.
  • Verify whether the request generates process-related security events.
  • Record the timestamp of the HTTP request.
  • Correlate the access event with the previously detected file creation.
Tools: Kali Linux + Apache HTTP Server + Wazuh
STEP 11

Step 11: Confirm the Web Shell Deployment Detection

  • Review Wazuh file-integrity events.
  • Identify the newly created server-side file.
  • Confirm the affected Apache directory.
  • Review related Apache process activity.
  • Correlate file creation with web-shell access activity.
  • Determine whether the combined events indicate suspicious web-server activity.
  • Document the initial detection result.
Tools: Wazuh + OpenSearch + Apache HTTP Server
STEP 12

Step 12: Analyze Security Events in OpenSearch

  • Open the security-event data collected by Wazuh.
  • Search for the file-integrity event associated with the controlled web-shell file.
  • Review the event timestamp.
  • Identify the affected file path.
  • Search for corresponding process activity.
  • Correlate the file and process events chronologically.
  • Record the evidence required for incident investigation.
Tools: OpenSearch + Wazuh
STEP 13

Step 13: Configure Automated Process Isolation

  • Configure the automated response mechanism for the identified suspicious process condition.
  • Define the detection condition that triggers the response.
  • Configure the response to isolate or terminate the associated suspicious process.
  • Ensure that the response is restricted to the controlled laboratory environment.
  • Verify the response configuration.
  • Confirm that the response action is logged.
Tools: Wazuh + Ubuntu
STEP 14

Step 14: Validate Automated Response

  • Repeat the controlled web-shell execution test.
  • Monitor Wazuh for the corresponding file-integrity event.
  • Observe the associated process activity.
  • Verify that the configured detection condition is triggered.
  • Confirm that the automated response is executed.
  • Verify that the suspicious process is isolated or terminated according to the configured policy.
  • Record the response timestamp and result.
Tools: Kali Linux + Wazuh + Ubuntu
STEP 15

Step 15: Validate File Integrity After Response

  • Review the monitored Apache directory.
  • Confirm that the controlled malicious file is identified.
  • Check the integrity state of the affected directory.
  • Verify whether the suspicious file remains accessible.
  • Confirm that the process associated with the test activity is no longer executing.
  • Record the final file and process state.
Tools: Ubuntu + Wazuh + OpenSearch
STEP 16

Step 16: Test Legitimate Apache Activity

  • Access legitimate Apache application files.
  • Send normal HTTP requests from Kali Linux.
  • Verify that legitimate Apache processes continue functioning.
  • Confirm that normal application activity does not trigger the automated isolation response.
  • Review Wazuh events for false-positive detection.
  • Verify that legitimate web-server functionality remains available.
Tools: Kali Linux + Apache HTTP Server + Wazuh
STEP 17

Step 17: Perform Re-Test of Web Shell Deployment Detection

  • Repeat the controlled web-shell deployment assessment.
  • Create the controlled test file within the monitored directory.
  • Access the file through the Apache service.
  • Verify that Wazuh detects the file-integrity change.
  • Verify that related process activity is detected.
  • Confirm that the automated process-isolation mechanism operates correctly.
  • Compare the post-remediation result with the original detection assessment.
Tools: Kali Linux + Wazuh + OpenSearch + Apache HTTP Server
STEP 18

Step 18: Perform Final Cyber Defense Validation

  • Perform a final web-server security assessment.
  • Re-test file creation detection.
  • Re-test file modification detection.
  • Re-test process monitoring.
  • Re-test file and process-event correlation.
  • Verify automated process isolation.
  • Review Wazuh alerts and OpenSearch events.
  • Confirm that legitimate Apache activity continues to function.
  • Document the final detection and response results.
Tools: Wazuh + OpenSearch + Apache HTTP Server + Kali Linux + Ubuntu
STEP 19

Step 19: Document the Final Incident Response Assessment

  • Document the original web-shell deployment behavior.
  • Record the affected Apache web directory.
  • Document the detected file-integrity event.
  • Record the related process activity.
  • Document the automated process-isolation action.
  • Record the post-response server state.
  • Confirm that the web-shell deployment was detected.
  • Confirm that the associated suspicious process was isolated according to the configured response.
  • Maintain the final security assessment as evidence of the completed web-shell detection and response workflow.
Tools: Wazuh + OpenSearch + Apache HTTP Server + Ubuntu + Kali Linux

Outcome

  1. The web-shell deployment attack is successfully assessed against the controlled Apache HTTP Server environment.
  2. The assessment demonstrates the security risk created when malicious server-side files are introduced into web-accessible Apache directories.
  3. The Apache document root and critical web-server files are identified and placed under file-integrity monitoring.
  4. Controlled web-shell deployment generates file-integrity events that can be detected by Wazuh.
  5. File creation and modification activity is correlated with associated Apache process behavior.
  6. OpenSearch provides centralized analysis of file-integrity, process, and response events.
  7. Automated process isolation prevents the detected suspicious server-side process from continuing execution according to the configured response policy.
  8. Legitimate Apache application activity continues to function while suspicious web-shell activity is detected and contained.
  9. Security events provide evidence for investigation, validation, and incident-response analysis.
  10. Wazuh, OpenSearch, Apache HTTP Server, Ubuntu, Kali Linux, and VirtualBox are used to demonstrate the complete web-shell deployment detection, file-integrity monitoring, automated process-isolation, and post-response security-validation workflow.