🚀 Available for Freelance, Remote, and Full-Time Opportunities. Let's build something amazing together.

Laravel Packages
1 min read

Laravel Scalpel Scans for Filesystem Intrusion Evidence

Laravel Scalpel is a security package that scans your project filesystem for indicators of compromise, webshell backdoors, unexpected executable files, and altered vendor code.

A

Author

2 weeks ago

Auditing Filesystem Integrity with Laravel Scalpel

Even with strict server configuration, compromised file uploads or third-party vulnerabilities can leave subtle webshells or rogue PHP scripts in storage or public directories. Laravel Scalpel is an incident response and forensic auditing tool built specifically for Laravel projects.

Forensic Detection Engines

Laravel Scalpel evaluates your application through multiple distinct security layers:

  • Vendor Integrity Hashing: Compares files inside vendor/ against Composer lockfile distribution hashes to verify that core vendor packages have not been tampered with.
  • Webshell Heuristics: Detects dangerous PHP functions (eval(), base64_decode(), proc_open()) concealed inside non-code asset directories.
  • Public Directory Verification: Alerts if executable PHP or shell scripts exist inside public/storage or file upload paths.
  • Hidden File Audits: Uncovers suspicious dotfiles and unusual file permission configurations across application roots.

Running an Intrusion Scan

# Run complete filesystem scan
php artisan scalpel:scan --strict

# Schedule daily automated health checks
$schedule->command('scalpel:scan --notify-on-failure')->dailyAt('04:00');

Laravel Scalpel provides peace of mind for engineering teams operating mission-critical production environments.