Web Shell Command Execution via HTTP POST - PHP/ASPX/JSP

Detects incoming HTTP POST requests directed at PHP, ASPX, or JSP files that contain suspicious command execution patterns (such as cmd=, exec=, system(, or eval()). This behavior is highly indicative of an attacker interacting with a web shell to execute unauthorized commands on the server.