Using Log Parsing to Stop Microsoft IIS Backdoor Attacks

EclecticIQ
EclecticIQ Blog
Published in
7 min readNov 23, 2022

--

Chances are you’ve heard of Microsoft’s Internet Information Services, (more commonly known as IIS) as it’s one of the most popular web servers in the world, boasting a user base of over one million websites and included in the tech stack of nearly 6,000 companies. Being popular is great, but it also means becoming a bigger target — just ask Microsoft, who recently warned users about the growing trend of threat actors planting backdoors into Exchange servers via IIS extensions.

--

--

EclecticIQ
EclecticIQ Blog

EclecticIQ is a global provider of threat intelligence technology and services. Our clients are some of the most targeted organizations, globally.