Web evidence
Access logs, error logs, POST requests, upload behavior, suspicious keywords, and request timing help locate entry clues.
Open Investigator · WebShell investigation
A WebShell alert often starts from a path, upload, request keyword, suspicious process, or changed file. Open Investigator turns those clues into a local evidence workflow.
Search intent
Practical workflow
Access logs, error logs, POST requests, upload behavior, suspicious keywords, and request timing help locate entry clues.
Recent JSP, PHP, ASP, JAR, WAR, CLASS, and script changes are checked against process, network, user, and persistence context.
Findings keep supporting evidence IDs and gaps so a responder can validate whether the clue is benign, suspicious, or likely compromise.
Common searches
The source, usage examples, contribution notes, and issue tracker live in the public Open Investigator repository.