WEB SHELL SALDIRI TÜRÜNÜN WİNDOWS FORENSİC TEKNİKLERİYLE ANALİZ EDİLMESİ

dc.contributor.advisorTUNCER, TÜRKER
dc.contributor.authorDAĞCI, KEVSER MEHVEŞ
dc.date.accessioned2026-08-12T10:09:52Z
dc.date.issued2022
dc.departmentFÜ, Fen Bilimleri Enstitüsü, Adli Bilişim Mühendisliği Anabilim Dalı
dc.description.abstractGünümüzde iletişim teknolojilerinin hızla yaygınlaşması ve internet kullanımının artması ile siber saldırılar gün geçtikçe artmaktadır. Meydana gelen siber saldırılar sonucunda; kurumlar maddi ve itibar kaybı gibi büyük kayıplar yaşamaktadırlar. Siber saldırıların geç tespiti, analistlerin yetkinliği ve verilerin ayrıştırılma sürecinde yaşanan aksaklıklar saldırıların zarar boyutunu arttırmaktadır. Bu yüzden meydana gelen saldırıların erken tespiti önem arz etmektedir. Özellikle sistemlere erişim sağladıktan sonra uzun süre sistem içerisinde yıllarca fark edilmeden kalabilen gruplar bulunmaktadır. Bu gruplar APT (Advanced Persistent Threat: Gelişmiş Kalıcı Tehdit) grupları olarak adlandırılıp web shell saldırı türünü sık olarak kullanmaktadırlar. Saldırganların hedef sisteme birden fazla Shell yükleme yöntemi ile erişme olanağı bulunmaktadır. Shell dosya kodu yüklenen sistemlerde saldırganlar erişim yetkisine sahip olarak sistemler üzerinde kötücül aktiviteler gerçekleştirebilmektedir. Bu tezin amacı siber güvenlik dünyasında bulunan ve bu alanda ilgili olan kişilerin bir web Shell saldırısı ile karşılaştıklarında ilk olarak hangi işlemleri yaparak sistemleri kontrol edebileceği ve alınabilecek önlemleri içermektedir. Bu tez çalışmasında bir sistem üzerine web shell yüklemesi yapıldıktan sonra Windows sistemler üzerinde nasıl analiz edilerek tespit edildiği açıklanmış ve adli bilişim açısından analizinin nasıl gerçekleştirilmesi gerektiği ortaya konulmuştur. Tez çalışmasının uygulama bölümünde, saldırı sonrası içerisine file upload yöntemi ile shell yüklemesi yapılmış ve imajı alınmış sistemin analizi gerçekleştirilmiştir. Çalışma sırasında kullanılan analiz yöntemlerinin hepsi açık kaynak kodlu ve ücretsiz yazılımlardır.
dc.description.abstractToday, with the rapid spread of communication technologies and the increase in internet use, cyber attacks are increasing day by day. As a result of cyber attacks; Institutions experience great losses such as financial and reputational loss. The late detection of cyber attacks, the competence of analysts and the disruptions in the data separation process increase the damage size of the attacks. Therefore, early detection of attacks is important. Especially after gaining access to the systems, there are groups that can remain unnoticed for years in the system for a long time. These groups are called APT (Advanced Persistent Threat) groups and frequently use the web shell attack type. Attackers have the opportunity to access the target system with more than one shell installation method. In systems with shell file code installed, attackers can perform malicious activities on systems with access privileges. The aim of this thesis is to include the precautions that can be taken and what actions can be taken by the people in the world of cyber security and who are interested in this field, when they encounter a web shell attack. In this thesis, it is explained how it is analyzed and detected on Windows systems after web Shell is installed on a system, and how the analysis should be carried out in terms of forensic computing is revealed. In the application part of the thesis, after the attack, the shell was uploaded with the file upload method and the image of the system was analyzed. All of the analysis methods used during the study are open source and free software.
dc.identifier.citationDAĞCI, K. (2022). Web shell saldırı türünün windows forensic teknikleriyle analiz edilmesi (Tez No. 742482) [Yüksek lisans tezi, Fırat Üniversitesi].
dc.identifier.urihttps://tez.yok.gov.tr/UlusalTezMerkezi/TezGoster?key=sELqxhTlFGAjsbjOuuiyCANgvaXjYrOmkv9mf0zQC3BOvMyxM_9RJIvxlCHTZ6wH
dc.identifier.urihttps://hdl.handle.net/11508/22558
dc.identifier.yoktezid742482
dc.language.isotr
dc.publisherFırat Üniveristesi
dc.relation.publicationcategoryTez
dc.rightsinfo:eu-repo/semantics/openAccess
dc.snmzKA_TEZ_20260511
dc.subjectSavunma ve Savunma Teknolojileri
dc.titleWEB SHELL SALDIRI TÜRÜNÜN WİNDOWS FORENSİC TEKNİKLERİYLE ANALİZ EDİLMESİ
dc.title.alternativeAnalyzing web shell attack type with windows forensic techniques
dc.typeMaster Thesis

Dosyalar