All projects
2026 Author

Houndoom

Web shell and backdoor scanner in Go

I wrote Houndoom to investigate websites after a compromise: find web shells and backdoors, inspect suspicious files, and prepare for cleanup. It is written in Go and builds into a single binary, with dedicated checks for WordPress and Bitrix.

Each finding includes a file path, line number, matched rule, and code excerpt. The scanner runs locally or over SSH. Remote scans upload a binary to a temporary directory, retrieve the report, and remove temporary files. Findings can also be reviewed with Claude; the main scan works without AI.

Features

  • Signature and rule checks for web shells, backdoors, and malicious JavaScript
  • Checks that account for WordPress and Bitrix directory structure
  • Static PHP deobfuscation that decodes supported layers without executing the code
  • SSH scans with a temporary binary upload and report retrieval
  • Optional Claude analysis via --ai, which sends code excerpts to Anthropic
  • Three scan modes and HTML, JSON, Markdown, XML, and plain text reports

Technologies

Go Claude AI CLI