Laravel Scalpel: A New Way to Detect Filesystem Intrusions in Laravel
Laravel applications can be compromised in ways that traditional code and dependency scanners may not catch. Laravel Scalpel takes a different approach by looking for evidence that a deployed application has already been modified or compromised.
It can detect:
• Rogue PHP files and suspicious extensions
• Obfuscated PHP and common backdoor patterns
• Malicious .htaccess and .user.ini changes
• Unexpected .env files and configuration issues
• Added, modified, or deleted files using SHA-256 baselines
• Changes that can be integrated into CI/CD security checks
It also supports JSON, SARIF, and GitHub Actions output, making it interesting for teams that want to incorporate filesystem integrity checks into their deployment pipelines.
One important limitation: Scalpel runs with the same permissions as the Laravel application, so it should be treated as a detection tool rather than a complete security or containment solution.
For Laravel teams, this is an interesting additional layer for detecting signs of post-deployment compromise.
#Laravel #PHP #Cybersecurity #ApplicationSecurity #DevSecOps #WebSecurity #SoftwareDevelopment #CI_CD
https://laravel-news.com/laravel-scalpel
About This Hashtag
#applicationsecurity
4 posts
Last used 1d
#applicationsecurity
4 posts· Last used 1d
📢 How Web Cache Poisoning works — Complete Guide | Bug Bounty Course Day 29 of 60
Master web cache poisoning bug bounty 2026. Unkeyed headers, Vary header abuse, cache buster techniques, Burp Suite detection and real HackerOne payout examples.
🔗 https://securityelites.com/day-29-web-cache-poisoning-bug-bounty/
#ageheader #applicationsecurity #bugbounty
🚨 The biggest mistake in modern web security? Believing your WAF is enough.
For years, we were taught:
Deploy a Web Application Firewall and you're protected.
That mindset no longer matches how many real-world attacks work.
Today's attackers increasingly focus on:
🔓 Broken Authorization (BOLA/BFLA)
🔑 Identity & OAuth/JWT abuse
🔌 API vulnerabilities
🧠 Business Logic flaws
⚡ Race Conditions
🤖 Legitimate functionality abused in unintended ways
These attacks often don't rely on payloads that a WAF is designed to block.
Instead, they exploit trust.
As cybersecurity professionals, we need to think beyond signatures and filtering rules. Understanding how attackers chain application logic, identities, and APIs together is becoming just as important as finding SQL injection or XSS.
I wrote an article exploring this shift in modern application security.
📖 Read it here:
👉 https://danielisaace.hashnode.dev/stop-trusting-your-waf-modern-attackers-have-already-moved-on
I'm curious to hear from the community:
What do you think is the most overlooked attack vector in modern web applications today?
Your perspective might help someone else rethink their security strategy.
#CyberSecurity #ApplicationSecurity #AppSec #WebSecurity #API #OWASP #EthicalHacking #PenetrationTesting #DevSecOps #SecurityResearch #CyberDefense #InfoSec
We're excited to celebrate an important milestone for two of our teammates, Matei Buzdea and Luca Molteni, as they transition from interns to full-time security consultants! 🎉
From day one, they've demonstrated curiosity, technical skill, and a passion for application security. Throughout their internships, they've contributed to client engagements, collaborated with our team, and continued to grow as security professionals.
Investing in talented people and helping them develop into exceptional consultants is something we're proud of. We can't wait to see what they'll accomplish in this next chapter.
Congratulations on making it official, we're excited to have you both on the team full time! 🚀
#ApplicationSecurity #AppSec #PenTesting #CyberSecurity #CareerGrowth #internships #doyensec #security
You've seen all posts