.png)
GreyNoise has historically focused on scanning and exploitation at the internet's edge, the left of MITRE ATT&CK; GreyNoise Tactics now sees the right of the shell, what an attacker does after they land one.
"After the Shell" is the first public report from GreyNoise Tactics. We read more than 110,000 host sessions, command by command. The finding: volume did not predict risk. The busiest targets were almost never the dangerous ones. Serious activity was rare, fewer than 1 in 1,000 sessions, and it concentrated on quiet, credential-rich services.
One React2Shell session went the furthest. React2Shell (CVE-2025-55182) is a server-side deserialization flaw that gives remote code execution. In this session, an automated toolkit ran from a landed shell to cloud credentials, a backdoor superuser, and a container escape onto the host, in about 82 minutes with no human at the keyboard. The report walks it command by command.
Download the report to see what attackers do after they get in, which of your services they go for, and how to tell the session that matters from the noise.
Fill out the form to download your free copy.
GreyNoise has historically focused on scanning and exploitation at the internet's edge, the left of MITRE ATT&CK; GreyNoise Tactics now sees the right of the shell, what an attacker does after they land one.
"After the Shell" is the first public report from GreyNoise Tactics. We read more than 110,000 host sessions, command by command. The finding: volume did not predict risk. The busiest targets were almost never the dangerous ones. Serious activity was rare, fewer than 1 in 1,000 sessions, and it concentrated on quiet, credential-rich services.
One React2Shell session went the furthest. React2Shell (CVE-2025-55182) is a server-side deserialization flaw that gives remote code execution. In this session, an automated toolkit ran from a landed shell to cloud credentials, a backdoor superuser, and a container escape onto the host, in about 82 minutes with no human at the keyboard. The report walks it command by command.
Download the report to see what attackers do after they get in, which of your services they go for, and how to tell the session that matters from the noise.
Fill out the form to download your free copy.