All projects
2026 Author
Houndoom
Web shell and backdoor scanner in Go
I wrote Houndoom to investigate websites after a compromise: find web shells and backdoors, inspect suspicious files, and prepare for cleanup. It is written in Go and builds into a single binary, with dedicated checks for WordPress and Bitrix.
Each finding includes a file path, line number, matched rule, and code excerpt. The scanner runs locally or over SSH. Remote scans upload a binary to a temporary directory, retrieve the report, and remove temporary files. Findings can also be reviewed with Claude; the main scan works without AI.
Features
- Signature and rule checks for web shells, backdoors, and malicious JavaScript
- Checks that account for WordPress and Bitrix directory structure
- Static PHP deobfuscation that decodes supported layers without executing the code
- SSH scans with a temporary binary upload and report retrieval
- Optional Claude analysis via --ai, which sends code excerpts to Anthropic
- Three scan modes and HTML, JSON, Markdown, XML, and plain text reports
Technologies
Go Claude AI CLI