This toolkit was born from responding to a real incident: a hosting account with 24 sites and 51 databases where an attacker maintained unauthorized access for several weeks, spreading malware through folders believed to be backups.
The process I automated covers four fronts that repeat in nearly any intrusion of this kind: cross-directory scanning to find malicious files duplicated across multiple locations (including ones disguised as backups), admin-account auditing to detect the staggered-creation patterns typical of persistent unauthorized access, checking for public exposure of database backups and scripts with embedded credentials, and automatic classification of orphaned versus active databases in accounts with dozens of them.
The methodology has already been applied across multiple audits with nearly identical attack patterns — unlicensed premium software as a recurring entry vector, contaminated "backup" folders — confirming it's worth keeping standardized and ready instead of rebuilding it per client.
← Back to projects