A security team discovers that an attacker maintained persistence in their environment for 9 months using a web shell. Which log source would MOST likely have revealed this activity earliest?
-
A
Active Directory authentication logs showing failed login attempts
-
B
Web server access logs showing unusual POST requests to the web shell path
-
C
Network flow data showing large outbound data transfers
-
D
Endpoint antivirus logs from the web server