What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Investigate a suspected NetScaler compromise as an incident involving both the appliance and the systems connected to it. Review HTTP access and error records, shell logs, files and startup changes, sessions, outbound traffic, directory-service activity, and potentially affected systems. A patch can close the vulnerability used to get in; it does not establish that an attacker’s existing webshell, account access, or other foothold has been removed.

The indicators below include examples from specific Citrix campaigns, not a universal signature. Treat a suspicious request as a lead, then correlate it with appliance artifacts, timelines, and related identity or network evidence.

What evidence should you collect first?

Start by establishing what the appliance does and what records are available. Preserve relevant appliance, network, and identity records under your organization’s incident-response and evidence-handling procedures. The CISA advisories cited below identify useful artifacts, but do not prescribe one evidence-acquisition sequence or chain-of-custody process for every NetScaler version.

  • Record the appliance type, deployment role, software version, management and traffic interfaces, exposure, and suspected incident dates.
  • Identify which logs are retained locally and which are available from centralized logging, monitoring, identity, or network systems.
  • Preserve available records, including rotated or compressed logs, before routine retention or log rotation removes them.
  • Record the time zone and clock context for each source so events can be correlated. Keep a timeline of collection and response actions according to your incident procedures.

Which appliance logs should you review?

Review several log families together. CISA’s 2023 advisory, Threat Actors Exploiting Citrix CVE-2023-3519 to Implant Webshells (AA23-201A), and its 2020 advisory, Detecting Citrix CVE-2019-19781 (AA20-031A), identify HTTP access and error logs, NetScaler shell logs, and VPN HTTP access logs as useful sources.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
  • HTTP access and error logs: Look for unfamiliar successful requests, suspicious paths, and sequences that may indicate exploitation or interaction with a webshell.
  • httpaccess-vpn.log*: For the CVE-2023-3519 activity described by CISA, review successful access to unknown web resources and correlate connections or sessions by source IP. Excessive activity from one IP may indicate webshell interaction.
  • sh.log* and bash.log*: Look for unexpected commands and note the associated user or process context. Include rotated records where available.
  • Related records: The earlier CISA advisory also identifies notice.log as a source to review. Interpret any entry in the context of normal administration and documented changes.

How to interpret campaign-specific log indicators

For CVE-2019-19781, CISA specifically calls out httpaccess.log and httperror.log, suspicious /../vpns/ paths, and POST requests followed by GET requests to XML files. The advisory also recommends identifying the source IP address. These are historical, vulnerability-specific indicators; their absence does not rule out another kind of compromise, and a matching request alone does not prove that an attacker established access.

For the CVE-2023-3519 campaign, CISA lists shell-log search terms including database.php, ns_gui/vpn, /flash/nsconfig/keys/updated, LDAPTLS_REQCERT, ldapsearch, and openssl + salt. Use them as leads tied to the described campaign, not as a complete detection rule. Check suspicious entries against expected administrative activity and change records.

How can you look for webshells and persistence?

Do not limit the review to the initial request or a single suspicious file. Examine the appliance for unauthorized web content or scripts, unexpected cron jobs, unusual processes, and changes to startup or configuration files. Compare findings with known-good configuration and authorized changes where those records are available.

  • Look for web content or scripts that administrators do not recognize, and determine whether access logs show requests to them.
  • Review cron jobs and their ownership. CISA’s CVE-2019-19781 advisory flags cron jobs created by nobody as a suspicious example; verify the context rather than treating the owner alone as proof.
  • Check for unexpected processes and shell or startup changes.
  • Review rc.netscaler for unauthorized modifications. CISA’s 2023 advisory describes an attacker changing it to set shell permissions and rewrite a webshell at reboot—a persistence pattern that can survive a restart.

CISA’s earlier advisory also describes reviewing bash.log and sh.log for activity by nobody or (null) on. These are investigation leads, not stand-alone proof of compromise. Validate them against the appliance’s expected use and recorded administrative work.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

How do you assess sessions and systems beyond the appliance?

Correlate appliance sessions and source IP addresses over the suspected period with network and identity records. Look for unusual session patterns, excessive connections, and large outbound transfers over short intervals. Determine whether activity continued after a vulnerability was patched or an appliance was restarted.

Citrix Bleed, CVE-2023-4966, can expose sensitive information including session authentication-token information that may enable session hijacking. Use current Citrix guidance to review active and persistent sessions and assess affected accounts. CISA’s page for the 2023 event contains historical version guidance; it is not a substitute for checking current Citrix security bulletins before making production changes in 2026.

  • Review directory-service authentication records for authentication from the appliance IP using the account configured for that connection.
  • Check failed logons where the relevant restriction scenario applies, as described in CISA’s 2023 guidance.
  • When appliance evidence or timeline correlation suggests follow-on activity, expand the review to connected systems and identity infrastructure.
  • Look for the follow-on behaviors documented in CISA’s MAR-10478915-1.v1 Citrix Bleed analysis, including files used to save registry hives, LSASS process-memory dumps written to disk, and attempted WinRM sessions. These are behaviors in that report, not evidence that every NetScaler incident includes them.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

What distinguishes an attempted attack from a confirmed compromise?

A suspicious request or scan can show that someone tried to reach the appliance; on its own, it does not establish successful execution or a persistent foothold. Strengthen or weaken that hypothesis by correlating the request’s time and source with shell activity, suspicious files, processes, startup changes, sessions, and activity on connected systems.

Keep the questions separate: was a vulnerable appliance targeted, did code or commands execute, was persistence established, and did activity extend to accounts or other systems? Evidence for one does not automatically answer the others. Indicators from the CVE-2019-19781 or CVE-2023-3519 campaigns are useful in those contexts, but are not complete signatures for every NetScaler compromise.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

What should you do if you find evidence of compromise?

Coordinate containment and recovery with incident leadership. CISA’s 2023 advisory recommends quarantining or taking potentially affected hosts offline, reimaging compromised hosts, provisioning new account credentials, and collecting and reviewing running processes and services, unusual authentications, and recent network connections. The Citrix Bleed guidance also urges organizations to update unmitigated appliances, hunt for malicious activity, and report positive findings.

  1. Coordinate containment: Decide with incident leadership whether affected hosts should be quarantined or taken offline, balancing containment with evidence preservation and operational needs.
  2. Address the vulnerability: Check current Citrix security bulletins for applicable remediation and plan production changes for the specific appliance and environment.
  3. Remove the foothold: Treat confirmed compromise as a recovery problem, not only a patching task. Follow incident-response guidance for reimaging compromised hosts and validating the recovered environment.
  4. Address credentials and sessions: Provision new account credentials as appropriate, and assess sessions and accounts using current Citrix guidance—particularly where session-token exposure is suspected.
  5. Check the broader environment: Review processes, services, authentications, recent network connections, directory-service records, and connected systems for related activity.

CISA’s 2020 Citrix detection advisory explicitly warns that patching does not remediate actors who already established a foothold. A fixed version and a cleaned appliance are different outcomes; confirm both rather than treating one as evidence of the other.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.