Web Shells
3
cmd_shell.aspx
upload.aspx
backdoor.ashx
Suspicious Services
2
RemoteAccess
New Users
1
svc_backup
RDP Status
ENABLED
Administrator Group Members
Administrator
COLONIAL\DomainAdmins
svc_backup
Recent Alerts (4)
WEB_SHELL3 web shell(s) detected
2 hours agoNEW_USER1 new user account(s) detected
2 hours agoRDPRDP is enabled on this system
2 hours agoSERVICE2 suspicious service(s) detected
2 hours agoAudit History (1)
CRITICAL
3 shells, 2 services, 1 new usersJan 27, 2026, 07:18:00 AM