Linux Malware Detect (maldet) vs Shelltrap
maldet is free, GPL-2.0 and still shipping releases. The real question is the signature feed behind it — measured, with commands to re-check it yourself.
Security research
Sourced writing on webshells, server-side malware and the operational reality of defending shared hosting. Every factual claim carries a link to its primary source.
maldet is free, GPL-2.0 and still shipping releases. The real question is the signature feed behind it — measured, with commands to re-check it yourself.
Germany's NIS2 law is in force since 6 December 2025. What it obliges hosters to do, what the BSI requires, and how a local-only scanner answers it.
Deleting a detected file destroys your evidence and your undo button. When quarantine is the right default, and what a usable quarantine record contains.
Isolation and blindness are one property seen from two sides. What CageFS protects, what a per-tenant scanner cannot see, and how to sweep a whole box.
What a real report-only rollout looks like: the install order, the eight numbers to watch, the abort criteria and what our own first host actually did.
A signature feed is a supply chain into your server. Ed25519 signing, per-rule provenance, activation gates, rollback, and why feed age belongs in health.
Sourced campaigns, CVE chains and file-level indicators from the 2024–2026 WordPress backdoor wave — with the dates, the caveats and the counter-example.
A webshell is a script an attacker leaves behind in your web root to keep access. What they look like on disk, how they persist and what finds them.
Twelve questions for a malware-scanner purchase, mapped to the EU supplier clauses and Art. 28 GDPR, plus the exit questions the cxs wind-down taught us.
Plugin scanners share the fate of the process they run in. What kernel docs, MITRE, the NSA repo and the BSI say about watching writes below the tenant.
An in-process PHP scanner shares the fate of the process it runs in. The architectural differences, from both vendors' own docs and Sucuri's casework.
Cleaning a hacked WordPress site from the host, in order: preserve evidence, contain, inventory, check the neighbours, patch, and prove it stayed clean.