mirror of
https://github.com/mukul975/Anthropic-Cybersecurity-Skills.git
synced 2026-07-29 07:30:59 +03:00
- Fix 25 shell=True subprocess calls with list-based commands - Fix 49 verify=False in defensive skills (env-var override) - Add timeout to 231 HTTP/subprocess/socket calls - Fix 6 SQL injection patterns with whitelist validation - Replace 8 __import__() with standard imports - Remove 701 unused imports across 442 files - Add authorized-testing disclaimers to all offensive skills - Complete 11 incomplete skill directories - Expand 10 stub SKILL.md files with full content - Fix 2 YAML parse errors in frontmatter - Fix 5 pre-existing syntax errors - Convert 22 hardcoded paths/ports to environment variables - Back up 21 redundant skill pairs to .bak - Fix 2 global declaration errors - 724/724 skills with full folder anatomy (SKILL.md + agent.py + api-reference.md + LICENSE) - 0 compile errors across all 724 agent.py files
1.7 KiB
1.7 KiB
API Reference: Hunting for Webshells in Web Servers
Shannon Entropy Calculation
import math
def shannon_entropy(data: bytes) -> float:
freq = {}
for byte in data:
freq[byte] = freq.get(byte, 0) + 1
length = len(data)
return -sum((c/length) * math.log2(c/length) for c in freq.values())
# Thresholds: > 5.5 suspicious, > 6.5 likely obfuscated
Webshell Detection Patterns
| Pattern | Language | Risk |
|---|---|---|
eval() |
PHP | HIGH |
base64_decode() |
PHP | HIGH |
system() / passthru() |
PHP | CRITICAL |
shell_exec() / exec() |
PHP | CRITICAL |
$_GET/$_POST + eval |
PHP | CRITICAL |
Runtime.getRuntime().exec |
JSP | CRITICAL |
Server.CreateObject |
ASP | HIGH |
YARA Rule for Webshells
rule webshell_php_generic {
meta:
description = "Generic PHP webshell"
strings:
$eval = "eval(" ascii nocase
$b64 = "base64_decode(" ascii nocase
$system = "system(" ascii nocase
$input = /\$_(GET|POST|REQUEST)\s*\[/ ascii
condition:
$input and ($eval or $b64 or $system)
}
File System Scanning
from pathlib import Path
SCRIPT_EXTS = {".php", ".asp", ".aspx", ".jsp", ".jspx", ".cgi"}
for f in Path("/var/www/html").rglob("*"):
if f.suffix.lower() in SCRIPT_EXTS:
entropy = shannon_entropy(f.read_bytes())
NeoPI (Webshell Detection Tool)
python neopi.py /var/www/html -a # Run all tests
# Tests: entropy, longest word, index of coincidence, signature
References
- MITRE T1505.003: https://attack.mitre.org/techniques/T1505/003/
- NeoPI: https://github.com/Neohapsis/NeoPI
- YARA: https://yara.readthedocs.io/