Case 0006: Linux Web Server Hijack via cPanel Exploitation | Threat Hunting Labs

Hunt the cPanel intrusion from php-cgi execution through payload retrieval, webshell staging, UID 0 accounts, and anti-forensic cleanup.