Zennoxa Shield Documentation
Learn how to use every part of Shield — from your first scan to the CLI — plus the full reference for all 315 detection rules.เรียนรู้วิธีใช้ทุกส่วนของ Shield — ตั้งแต่สแกนครั้งแรกจนถึง CLI — พร้อมเอกสารอ้างอิงครบทั้ง 315 rule
Quickstart (CLI)
curl -sSL zennoxa.com/install | sh
shield login
shield scan . --submit --project YOUR-PROJECT-ID --org YOUR-ORG-ID
Conceptsแนวคิด
SAST, Secrets, DAST (dynamic + live), Containers, Infrastructure-as-Code, and Dependencies — in one scan.SAST, Secrets, DAST (สแกน + ยิงจริง), Containers, IaC และ Dependencies — ในการสแกนครั้งเดียว
Every rule carries a severity: critical, high, medium, low, or info.ทุก rule มีระดับ: critical, high, medium, low หรือ info
Flags whether vulnerable code is actually reachable in your app, not just present.บอกว่าโค้ดช่องโหว่ถูกเรียกใช้จริงในแอปมั้ย ไม่ใช่แค่มีอยู่
Ranks findings by real-world risk (severity weighted by reachability).จัดอันดับตามความเสี่ยงจริง (ความรุนแรงถ่วงด้วยการเข้าถึงได้)
Using Shieldวิธีใช้งาน Shield
Step-by-step how-to for each function.วิธีใช้แต่ละฟังก์ชันทีละขั้นตอน
Loginเข้าสู่ระบบ
First step: log in at zennoxa.comขั้นตอนแรก: เข้าสู่ระบบที่ zennoxa.com
- 1Open your browser and go to https://zennoxa.comเปิด browser แล้วไปที่ https://zennoxa.com
- 2Enter your email address and passwordกรอก Email และ Password ของคุณ
- 3Click "Sign In" — the Dashboard loads automaticallyคลิก "Sign In" — ระบบจะพาไปที่ Dashboard อัตโนมัติ
- 4If 2FA is enabled, enter the 6-digit code from your authenticator appถ้าเปิด 2FA ไว้ ให้กรอกรหัส 6 หลักจากแอป Authenticator ด้วย
1. Create a Project1. สร้างโปรเจกต์
Before scanning, create a project — one per repository.โปรเจกต์คือกลุ่มของ repository ที่คุณต้องการสแกน ก่อนสแกนโค้ด คุณต้องสร้างโปรเจกต์ก่อน (1 โปรเจกต์ต่อ 1 repository)
- 1Click Projects in the left sidebarคลิก Projects ที่เมนูด้านซ้าย
- 2Click the "+ New Project" button in the top-right corner — an inline "Create New Project" form opensคลิกปุ่ม "+ New Project" มุมขวาบน — จะมีฟอร์ม "Create New Project" เปิดขึ้นมา
- 3Enter a Project Name (e.g. "my-website") — the Slug auto-fills from the name and can be edited; both are requiredกรอกชื่อโปรเจกต์ (เช่น "my-website") — ระบบเติม Slug ให้อัตโนมัติจากชื่อ (แก้ไขได้) ทั้งชื่อและ slug ต้องกรอก
- 4Choose how to connect the repo: the "From GitHub" tab lets you pick a repository from your connected GitHub App, or the "Enter URL manually" tab accepts a GitHub, GitLab, Azure DevOps, Bitbucket, or self-hosted git URL over HTTPS (add an access token for private repos)(ไม่บังคับ) กรอก Repository URL ถ้าต้องการเชื่อมต่อกับ GitHub/GitLab
- 5Click "Create Project" — you're taken straight to the new project's pageคลิก Create — โปรเจกต์จะปรากฏในรายการทันที
- 6Note down the Project ID — you'll need it when scanning with the CLIจด Project ID ไว้ (ใช้ตอนสแกนด้วย CLI)
2. Trigger a Scanสั่งสแกนโค้ด — สแกนหาช่องโหว่ในซอร์สโค้ดของคุณ
You can scan in two ways: via the Web UI or the CLI. CLI is covered in section 7.คุณสแกนได้ 2 วิธี: ผ่าน Web UI หรือ CLI
- 1Click Projects in the sidebar, then click the project you want to scanคลิก Projects ที่เมนูซ้าย แล้วคลิกโปรเจกต์ที่ต้องการสแกน
- 2Click the "Trigger Scan" buttonคลิกปุ่ม "Trigger Scan"
- 3Pick the branch to scan from the dropdown (it defaults to the repo's default branch) — or click "Type branch name" to enter one manually if the list isn't availableกรอก Branch ที่ต้องการสแกน (เช่น main หรือ develop)
- 4Click Start Scan — status changes to RUNNINGคลิก Start Scan — สถานะจะเปลี่ยนเป็น RUNNING
- 5Wait — a live progress panel updates automatically and the page refreshes when the scan is done. (Tip: no repo connected yet? Use the "Try Demo Scan" button to scan a built-in vulnerable sample end-to-end.)รอสักครู่ หน้าจอจะอัปเดตอัตโนมัติเมื่อสแกนเสร็จ DONE
- 6When done, click Findings in the sidebar to review resultsเมื่อสแกนเสร็จ คลิก Findings ที่เมนูซ้ายเพื่อดูผลลัพธ์
3. View Findingsตรวจสอบช่องโหว่ที่พบและดูวิธีแก้ไข
The Findings page lists every vulnerability found in your code, with severity levels and fix suggestions.หน้า Findings แสดงช่องโหว่ทั้งหมดที่พบในโค้ด พร้อมระดับความรุนแรงและคำแนะนำวิธีแก้ไข
- 1Click Findings in the sidebar — all vulnerabilities are listed.คลิก Findings ที่เมนูซ้าย — จะเห็นรายการช่องโหว่ทั้งหมด
- 2Click a severity filter like Critical to see only that level.กดปุ่มกรองระดับความรุนแรง เช่น Critical เพื่อดูเฉพาะช่องโหว่วิกฤต
- 3Click "By Priority" to sort by real-world risk score, not just severity label.คลิก "By Priority" เพื่อเรียงตามความเสี่ยงจริง (ไม่ใช่แค่ระดับ)
- 4Sort by "By Priority" to see the findings with the highest computed risk score first, then work down the list.ช่องโหว่ที่มีป้าย KEV คือช่องโหว่ที่มีคนใช้โจมตีจริงแล้ว — แก้ก่อนเลย
- 5Click the › chevron on any row to expand the code snippet.คลิก › ที่แถวใดแถวหนึ่งเพื่อดูโค้ดที่มีปัญหา
- 6Click a finding's message to open its detail page. If an AI analysis has been generated for that finding, an "AI Analysis" card shows a plain-language explanation and a suggested fix.คลิกที่ข้อความ (message) ของช่องโหว่เพื่อเปิดหน้ารายละเอียด ถ้ามีการสร้างคำอธิบาย AI ไว้แล้ว จะเห็นการ์ด "AI Analysis" ที่อธิบายเป็นภาษาง่าย ๆ พร้อมแนวทางแก้ไข
4. Manage Usersจัดการผู้ใช้
Add, remove, and manage user permissions within your organization (Admin only).เพิ่ม ลบ และจัดการสิทธิ์ผู้ใช้ในองค์กร (เฉพาะ Admin)
- 1How to invite a new team member: In the sidebar's Admin section, click Usersวิธีเพิ่มสมาชิกใหม่เข้าทีม: คลิก Admin ที่เมนูซ้าย แล้วเลือก Users
- 2Click "Invite user"คลิก "Invite user"
- 3Enter the email address of the person you want to inviteกรอก Email ของผู้ที่ต้องการเชิญ
- 4Choose a Role: Admin (full access, manage users), Member (create projects & trigger scans), or Viewer (read-only)เลือก Role: Admin (จัดการทุกอย่าง รวมถึงผู้ใช้), Member (สร้างโปรเจกต์และสั่งสแกนได้), หรือ Viewer (ดูอย่างเดียว)
- 5Click Send invite — a temporary password is generated; copy it and share it securely with the user, who changes it after first loginคลิก Send invite — ระบบจะสร้างรหัสผ่านชั่วคราวให้ คัดลอกแล้วส่งให้ผู้ใช้อย่างปลอดภัย ผู้ใช้จะเปลี่ยนรหัสผ่านหลัง login ครั้งแรก
- 6The invited user appears in the Users list immediately and can log in with the temporary password you sharedผู้ใช้ที่ถูกเชิญจะปรากฏในรายการ Users ทันที และเข้าสู่ระบบได้ด้วยรหัสผ่านชั่วคราวที่คุณส่งให้
- 7How to remove a user: Go to Admin → Usersวิธีลบผู้ใช้ออกจากองค์กร: ไปที่ Admin → Users
- 8Find the user you want to remove and click the red trash (Delete) icon on their rowหาชื่อผู้ใช้ที่ต้องการลบ แล้วคลิก Remove
- 9Confirm the removal — that user can no longer log inยืนยันการลบ — ผู้ใช้คนนั้นจะไม่สามารถ login ได้อีกต่อไป
5. Set Up an API Keyสร้าง key สำหรับใช้งาน CLI หรือ GitHub Actions
API Keys are used for: CLI scanning, GitHub Actions, or direct API calls.API Key ใช้สำหรับ: สแกนด้วย CLI, รัน GitHub Actions, หรือเรียก API โดยตรง
- 1Click Settings in the left sidebarคลิก Settings ที่เมนูซ้าย
- 2Select API Keysเลือก API Keys
- 3Click "Create key"คลิก "Create key"
- 4Enter a Key name so you remember what this key is for, e.g. "GitHub Actions CI", and pick an expiration (30 days by default, or No expiry)กรอก Key name เพื่อจำว่า key นี้ใช้ทำอะไร เช่น "GitHub Actions CI" และเลือกวันหมดอายุ (ค่าเริ่มต้น 30 วัน หรือ No expiry)
- 5Copy the key immediately — it is shown only once. If you close the page, it cannot be retrievedคัดลอก key ทันที — key จะแสดงแค่ครั้งเดียว ถ้าปิดหน้าจอไปแล้วจะเรียกคืนไม่ได้
- 6Use a CLI token in the CLI: export SHIELD_CLI_TOKEN=shield_cli_... (or run `shield login` and paste the token). Dashboard API keys are branded znx_ and are for direct API calls / CI.ใช้ CLI token กับ CLI: export SHIELD_CLI_TOKEN=shield_cli_... (หรือรัน `shield login` แล้ววาง token)
export SHIELD_CLI_TOKEN=shield_cli_...6. Install the CLI6. ติดตั้ง CLI
The Shield CLI lets you scan code directly from your terminal — ideal for GitHub Actions or other CI/CD pipelines.Shield CLI ให้คุณสแกนโค้ดจาก terminal ได้โดยตรง เหมาะสำหรับใช้ใน GitHub Actions หรือ pipeline อื่น ๆ
- 1No prerequisites — the installer downloads a self-contained binary and verifies its SHA256 checksumไม่ต้องติดตั้งอะไรก่อน — ตัวติดตั้งจะดาวน์โหลด binary พร้อมใช้และตรวจ SHA256 checksum ให้อัตโนมัติ
- 2Run this command in your terminal:รันคำสั่งนี้ใน terminal:
- 3Verify the installation:ตรวจสอบว่าติดตั้งสำเร็จ:
- 4Log in with your API Key (created in section 5):Login ด้วย API Key (สร้างจากหัวข้อที่ 5):
curl -sSL zennoxa.com/install | sh
# or: brew install zennoxa/tap/shield
# or download a binary + SHA256SUMS: github.com/Zennoxa/shield/releasesshield version# ตั้งค่า CLI token (สำหรับ headless/CI)
export SHIELD_CLI_TOKEN=shield_cli_your_token_here
# หรือ Login แบบ interactive / Or login interactively (เปิด browser ไปที่ /settings/cli-tokens)
shield login7. Scan a Repository with the CLIสแกน repo ด้วย CLI
รันการสแกนจาก terminal ใน 1 คำสั่ง
- 1Open a terminal and navigate to your project's root directoryเปิด terminal แล้วไปที่ root ของ project ที่ต้องการสแกน
- 2Run this command (replace YOUR-PROJECT-ID with your Project ID from section 1, and YOUR-ORG-ID with your organization ID):รันคำสั่งนี้ (แทนที่ YOUR-PROJECT-ID ด้วย Project ID จากหัวข้อที่ 1 และ YOUR-ORG-ID ด้วย organization ID):
- 3To apply a zone policy (dev, staging, production):ถ้าต้องการระบุ branch ด้วย:
- 4Wait for the CLI to report scan completion (it prints the Scan ID)รอจนกว่า CLI จะพิมพ์ว่า scan เสร็จแล้ว (จะแสดง Scan ID)
shield scan . --submit \
--project YOUR-PROJECT-ID --org YOUR-ORG-ID \
--api-url https://zennoxa.comshield scan . --submit --project YOUR-PROJECT-ID --org YOUR-ORG-ID --zone productionshield scan . --submit --project ${{ vars.SHIELD_PROJECT }} --org ${{ vars.SHIELD_ORG }} --api-url https://zennoxa.com8. View Resultsดูผลลัพธ์
See scan results both on the Dashboard and in the terminal.ดูผลการสแกนได้ทั้งบน Dashboard และใน terminal
- 1On the web: Go to https://zennoxa.com and click Findings — results appear automaticallyบน Web: ไปที่ https://zennoxa.com แล้วคลิก Findings — ผลจะปรากฏอัตโนมัติ
- 2In terminal: shield scan prints a per-severity summary (critical/high/medium/low/info) after each scan. To browse or filter findings, use the web dashboard.ใน terminal: ดูรายการ findings ล่าสุดด้วยคำสั่งด้านล่าง
- 3On the Dashboard, click Findings and filter by project or severity levelคลิก Findings บน Dashboard แล้วกรองตามโปรเจกต์หรือระดับ severity ที่สนใจ
- 4Click a finding's message for details. If an AI analysis has been generated, an "AI Analysis" card shows a plain-language description and a suggested fix.คลิก rule name ใด ๆ เพื่อเปิดหน้า detail — ถ้ามีคำอธิบาย AI แล้ว จะเห็นการ์ด "AI Analysis" อธิบายภาษาง่าย ๆ พร้อมแนวทางแก้ไข
# ดูผลลัพธ์บน dashboard — CLI ไม่มีคำสั่ง list findings/scans
# เปิด https://zennoxa.com/findings (กรองตาม severity ในหน้าเว็บ)shield loginshield scan . --submit --project PROJECT-ID --org ORG-ID# The CLI has no `projects list` command — view projects at https://zennoxa.com/projects# The CLI has no `scans list` command — view scan history at https://zennoxa.com/scans# The CLI has no `findings list` command — filter at https://zennoxa.com/findings?severity=criticalRules Referenceรายการ Rules
Every rule Shield can raise — id, severity, CWE, what it detects, where it appears, and how to fix. Use search to filter. (Rule text is in English.)ทุก rule ที่ Shield ตรวจได้ — id, severity, CWE, เจออะไร, ดูตรงไหน, แก้ยังไง (พิมพ์ค้นหาเพื่อกรอง; ข้อความ rule เป็นภาษาอังกฤษ)
SAST — Source Code 223 rules
SHIELD-CPP-004criticalCWE-242Use of gets is inherently unsafeDetects gets() which performs an unbounded read from stdin and always risks buffer overflow.
C/C++ files via gets() pattern matching
Replace gets with fgets and a fixed buffer size.
SHIELD-CPP-008criticalCWE-78Command injection via systemDetects system() called with a variable or concatenated string enabling command injection.
C/C++ files via system + variable/concatenation pattern matching
Avoid the shell; use execve with a fixed argument vector and validated inputs.
SHIELD-CPP-009criticalCWE-78Command injection via popenDetects popen() with a variable or concatenated command string enabling command injection.
C/C++ files via popen + variable/concatenation pattern matching
Replace popen with a direct exec of a fixed program and sanitized arguments.
SHIELD-CSHARP-001criticalCWE-89SQL injection via string concatenation in SqlCommandDetects SqlCommand constructed by concatenating untrusted strings directly into the query text.
C# files via SqlCommand + concatenation pattern matching
Use parameterized queries with SqlParameter instead of concatenating values into the SQL string.
SHIELD-CSHARP-002criticalCWE-89SQL injection via string.Format or interpolation into queryDetects SQL query assembled with string.Format or interpolated string containing SELECT/INSERT/UPDATE/DELETE.
C# files via SQL + string.Format/interpolation pattern matching
Replace string.Format and interpolation with parameterized queries binding user input as SqlParameter values.
SHIELD-CSHARP-003criticalCWE-89SQL injection via ExecuteReader on interpolated stringDetects ExecuteReader/ExecuteScalar/ExecuteNonQuery running a command with interpolated string text.
C# files via Execute method + interpolated string pattern matching
Use parameterized commands rather than passing an interpolated SQL string to Execute methods.
SHIELD-CSHARP-004criticalCWE-78Command injection via Process.Start with concatenationDetects Process.Start with command or argument string built from concatenated untrusted input.
C# files via Process.Start + concatenation pattern matching
Pass a fixed executable path and supply arguments as a validated ProcessStartInfo.ArgumentList collection.
SHIELD-CSHARP-006criticalCWE-502Insecure deserialization via BinaryFormatter and similar formattersDetects BinaryFormatter, LosFormatter, NetDataContractSerializer, or ObjectStateFormatter Deserialize calls.
C# files via insecure formatter pattern matching
Replace BinaryFormatter and similar formatters with a safe serializer such as System.Text.Json without type name handling.
SHIELD-CSHARP-007criticalCWE-502Insecure deserialization via Json.NET TypeNameHandlingDetects Json.NET configured with TypeNameHandling.All, Auto, Objects, or Arrays enabling type-confusion attacks.
C# files via TypeNameHandling pattern matching
Set TypeNameHandling to None or use a strict SerializationBinder that allowlists safe types.
SHIELD-DART-001criticalCWE-89SQL injection via raw query interpolationDetects raw SQL executed with string-interpolated or concatenated user input.
Dart files via rawQuery/rawInsert/execute + interpolation/concatenation pattern matching
Use parameterized queries with whereArgs or positional argument lists instead of interpolation.
SHIELD-DART-002criticalCWE-78Command injection via shell process executionDetects Process.run/Process.start invoked through a shell enabling command injection.
Dart files via Process + shell pattern matching
Pass a fixed executable with an argument list and avoid runInShell with untrusted input.
SHIELD-DART-005criticalCWE-295Insecure certificate validation bypassDetects badCertificateCallback returning true disabling TLS validation enabling man-in-the-middle attacks.
Dart files via badCertificateCallback => true pattern matching
Never unconditionally trust certificates; validate the chain and host properly.
SHIELD-GEN-003criticalCWE-798AWS access key exposedMatches AWS access key ID pattern (AKIA followed by 16 alphanumeric characters) which grants AWS resource access.
All languages via regex pattern AKIA[0-9A-Z]{16}
Revoke the exposed key immediately and use IAM roles or environment variables for authentication.
SHIELD-GEN-004criticalCWE-321Private RSA/EC key material in sourceDetects PEM-formatted private key headers (RSA, EC, OpenSSH, DSA PRIVATE KEY) embedded in source code.
All languages via PEM header pattern matching
Remove the private key from the codebase immediately. Rotate the key. Use a secrets manager.
SHIELD-GEN-006criticalCWE-798GitHub personal access token exposedDetects GitHub PAT prefix ghp_ followed by 36 alphanumeric characters which grant repository access.
All languages via GitHub PAT pattern matching
Revoke the token immediately at github.com/settings/tokens and rotate secrets.
SHIELD-GEN-008criticalCWE-798JWT secret hardcodedDetects jwt_secret, jwt_key, or signing_key assigned to a quoted string of 8+ characters, allowing token forgery.
All languages via JWT secret assignment pattern
Generate a cryptographically random secret and load it from the environment.
SHIELD-GEN-012criticalCWE-798Stripe secret key exposedDetects Stripe secret key pattern (sk_live_ or sk_test_ followed by 24+ alphanumeric characters) which grants full API access.
All languages via Stripe secret key pattern matching
Revoke the key in the Stripe dashboard immediately and rotate secrets.
SHIELD-GO-001criticalCWE-89SQL Injection via string formattingDetects SQL database query methods called with fmt.Sprintf for string interpolation.
Go files via db.Query + fmt.Sprintf pattern matching
Use parameterized queries with ? or $N placeholders instead of fmt.Sprintf.
SHIELD-GO-002criticalCWE-89SQL Injection via string concatenationDetects SQL query methods called with + string concatenation operator.
Go files via database query + concatenation pattern matching
Use parameterized queries. Never concatenate user input into SQL strings.
SHIELD-GO-007criticalCWE-78Command injection via exec.Command with user inputDetects exec.Command calls with user input from HTTP request URL, Form, PostForm, Header, or Body.
Go files via exec.Command + request pattern matching
Never pass user input directly to exec.Command. Validate and allowlist commands and arguments.
SHIELD-JAVA-001criticalCWE-89SQL Injection via String ConcatenationDetects SQL statement execution methods (executeQuery, executeUpdate, execute) called with string concatenation.
Java files via SQL method + concatenation pattern matching
Use PreparedStatement with parameterized queries instead of concatenating input into SQL strings.
SHIELD-JAVA-002criticalCWE-78OS Command Injection via Runtime.execDetects Runtime.getRuntime().exec() called with concatenated string.
Java files via Runtime.exec + concatenation pattern matching
Avoid shell invocation; pass a fixed command with an argument array and validate all inputs.
SHIELD-JAVA-003criticalCWE-78OS Command Injection via ProcessBuilderDetects ProcessBuilder constructed with concatenated arguments.
Java files via ProcessBuilder + concatenation pattern matching
Use a fixed argument list and validate or allowlist any user-controlled arguments.
SHIELD-JAVA-004criticalCWE-502Insecure Java DeserializationDetects ObjectInputStream.readObject() or readUnshared() on untrusted data enabling remote code execution.
Java files via ObjectInputStream pattern matching
Avoid native serialization for untrusted data; use a safe format like JSON with strict type validation.
SHIELD-JAVA-005criticalCWE-502Insecure Deserialization via XMLDecoderDetects XMLDecoder instantiation which deserializes arbitrary objects and can execute attacker code.
Java files via XMLDecoder pattern matching
Do not use XMLDecoder on untrusted input; use a safe data-binding library with restricted types.
SHIELD-JAVA-014criticalCWE-295Trust-All TLS HostnameVerifierDetects HostnameVerifier.verify() method that returns true unconditionally, disabling host validation.
Java files via HostnameVerifier pattern matching
Remove the custom verifier and rely on the default hostname verification.
SHIELD-JAVA-017criticalCWE-917SpEL or OGNL Expression InjectionDetects parseExpression, getValue, or setValue methods called with concatenated input.
Java files via expression + concatenation pattern matching
Never evaluate expressions built from user input; use a fixed expression with bound variables.
SHIELD-JAVA-018criticalCWE-917Log4Shell JNDI Lookup InjectionDetects jndi lookup patterns ${jndi:...} in logged data which can trigger remote code execution via Log4j.
Java files via JNDI pattern matching
Upgrade Log4j and disable message lookups; never log unsanitized user input.
SHIELD-JS-001criticalCWE-89SQL Injection via string concatenationDetects SQL query methods (query, execute, db.run, pool.query) called with string concatenation using + operator.
JavaScript/TypeScript files via pattern matching on query method calls with + operator
Use parameterized queries or prepared statements instead of string concatenation.
SHIELD-JS-002criticalCWE-89SQL Injection via template literalDetects SQL query methods called with template literal interpolation using backticks and ${}.
JavaScript/TypeScript files via template literal pattern matching
Use parameterized queries with placeholders instead of template literals.
SHIELD-JS-005criticalCWE-95Dangerous eval() usageDetects calls to eval() function which executes arbitrary JavaScript code.
JavaScript/TypeScript files via eval() pattern matching
Remove eval(). Use JSON.parse() for data or refactor to avoid dynamic code execution.
SHIELD-JS-009criticalCWE-78Command injection via exec/spawnDetects shell execution functions (exec, execSync, spawn) called with request.params/query/body.
JavaScript/TypeScript files via exec/spawn + request pattern matching
Avoid passing user input to shell commands. Use execFile with an argument array instead of exec.
SHIELD-KOTLIN-001criticalCWE-89SQL injection via string interpolation in rawQuery/execSQLDetects SQLiteDatabase rawQuery/execSQL called with Kotlin string template interpolating a variable.
Kotlin files via rawQuery/execSQL + string interpolation pattern matching
Use parameterized queries with selectionArgs placeholders instead of interpolating user input into SQL strings.
SHIELD-KOTLIN-002criticalCWE-89SQL injection via string concatenation in query APIsDetects SQL query methods called with + operator concatenation.
Kotlin files via SQL query + concatenation pattern matching
Use PreparedStatement with bound parameters or selectionArgs rather than concatenating strings.
SHIELD-KOTLIN-003criticalCWE-78Command injection via Runtime.exec with variableDetects Runtime.getRuntime().exec invoked with an interpolated or concatenated variable.
Kotlin files via Runtime.exec + variable pattern matching
Avoid shell execution with untrusted input; use a fixed argument array and validate inputs against an allowlist.
SHIELD-KOTLIN-004criticalCWE-78Command injection via ProcessBuilder with variableDetects ProcessBuilder constructed with an interpolated or concatenated variable.
Kotlin files via ProcessBuilder + variable pattern matching
Pass a static list of arguments and never build the command line from untrusted data.
SHIELD-KOTLIN-007criticalCWE-502Insecure deserialization via ObjectInputStream.readObjectDetects ObjectInputStream.readObject on untrusted data triggering remote code execution via gadget chains.
Kotlin files via ObjectInputStream.readObject pattern matching
Avoid Java native deserialization of untrusted input; use a safe format like JSON with strict schemas.
SHIELD-KOTLIN-014criticalCWE-295Trust-all TrustManager or HostnameVerifier disables TLS validationDetects empty checkServerTrusted or HostnameVerifier that always returns true disabling certificate validation.
Kotlin files via trust-all pattern matching
Perform full certificate and hostname validation; use certificate pinning for sensitive connections.
SHIELD-PHP-001criticalCWE-89SQL injection via string concatenation or interpolationDetects mysqli/PDO query calls built by concatenating or interpolating variables into the query.
PHP files via database query + concatenation/interpolation pattern matching
Use parameterized queries with bound placeholders instead of building SQL from variables.
SHIELD-PHP-002criticalCWE-89SQL injection via mysql_query with user inputDetects legacy mysql_query call including request superglobals or concatenated variables in the SQL.
PHP files via mysql_query + request pattern matching
Migrate to PDO or mysqli with prepared statements and bound parameters.
SHIELD-PHP-003criticalCWE-78OS command injection via shell execution functionsDetects shell execution functions (system, exec, shell_exec, passthru, popen, proc_open, pcntl_exec) with variables.
PHP files via shell execution function + variable pattern matching
Avoid shell calls with user data; use escapeshellarg/escapeshellcmd or safe library APIs.
SHIELD-PHP-004criticalCWE-78Command injection via backtick shell operatorDetects backtick execution operator running a shell command containing a variable.
PHP files via backtick shell operator + variable pattern matching
Do not use backtick execution with variables; validate input and use escapeshellarg.
SHIELD-PHP-005criticalCWE-95Code injection via eval or assert on variablesDetects eval, assert, or create_function receiving a variable allowing arbitrary PHP code execution.
PHP files via code execution function + variable pattern matching
Never pass dynamic input to eval/assert; refactor to avoid dynamic code evaluation.
SHIELD-PHP-006criticalCWE-95Code injection via preg_replace /e modifierDetects preg_replace with the deprecated /e modifier which evaluates the replacement as PHP code.
PHP files via preg_replace + /e modifier pattern matching
Replace the /e modifier with preg_replace_callback.
SHIELD-PHP-007criticalCWE-98File inclusion (LFI/RFI) via dynamic pathDetects include/require with a variable path enabling local or remote file inclusion.
PHP files via include/require + variable pattern matching
Include only from a fixed whitelist of allowed files; never use raw user input in paths.
SHIELD-PHP-009criticalCWE-502Unsafe deserialization of user inputDetects unserialize called on request data allowing object injection and remote code execution.
PHP files via unserialize + request superglobal pattern matching
Use json_decode for untrusted data or pass allowed_classes=>false to unserialize.
SHIELD-PY-001criticalCWE-89SQL Injection via string formattingDetects SQL execute methods called with % formatting, .format(), or f-string interpolation.
Python files via execute + string formatting pattern matching
Use parameterized queries with ? or %s placeholders instead of string formatting.
SHIELD-PY-002criticalCWE-89SQL Injection via f-string interpolationDetects SQL execute/query methods called with f-string literals containing variable interpolation.
Python files via execute + f-string pattern matching
Use parameterized queries. Never interpolate values directly into SQL strings.
SHIELD-PY-003criticalCWE-502Dangerous pickle deserializationDetects pickle.loads(), pickle.load(), or Unpickler calls which can deserialize arbitrary Python objects.
Python files via pickle deserialization pattern matching
Use JSON or another safe serialization format instead of pickle for untrusted data.
SHIELD-PY-004criticalCWE-95Dangerous exec() usageDetects exec() function calls which execute arbitrary Python code.
Python files via exec() pattern matching
Remove exec(). Refactor to use static code paths instead of dynamic code execution.
SHIELD-PY-005criticalCWE-78Shell injection via os.systemDetects os.system() calls which execute shell commands with user input.
Python files via os.system() pattern matching
Use subprocess.run() with a list of arguments and shell=False instead of os.system().
SHIELD-PY-008criticalCWE-95Insecure use of eval()Detects eval() calls which execute arbitrary Python code from strings.
Python files via eval() pattern matching
Remove eval(). Use ast.literal_eval() for safe expression parsing of known data structures.
SHIELD-RUBY-001criticalCWE-89SQL injection via string interpolation in whereDetects user input interpolated directly into an ActiveRecord where clause via #{} syntax.
Ruby files via where + string interpolation pattern matching
Use parameterized queries with placeholders such as where("col = ?", value).
SHIELD-RUBY-002criticalCWE-89SQL injection via find_by_sql interpolationDetects variables interpolated into find_by_sql building a query vulnerable to SQL injection.
Ruby files via find_by_sql + interpolation pattern matching
Pass an array with bind parameters to find_by_sql instead of interpolating.
SHIELD-RUBY-003criticalCWE-89SQL injection via execute interpolationDetects input interpolated into connection.execute allowing arbitrary SQL execution.
Ruby files via execute + interpolation pattern matching
Use exec_query with bind parameters or sanitize input before executing raw SQL.
SHIELD-RUBY-004criticalCWE-78Command injection via system or exec with interpolationDetects interpolated string passed to system or exec which runs it through a shell.
Ruby files via system/exec + interpolation pattern matching
Pass command and arguments as separate array elements to avoid shell interpretation.
SHIELD-RUBY-005criticalCWE-78Command injection via backticks or %x with interpolationDetects interpolated variables inside backticks or %x() executing attacker-controlled shell commands.
Ruby files via backticks/%x + interpolation pattern matching
Use Open3.capture2 with an argument array instead of backticks or %x with interpolation.
SHIELD-RUBY-007criticalCWE-95Code injection via evalDetects variable or interpolated string passed to eval executing arbitrary Ruby code.
Ruby files via eval + variable/interpolation pattern matching
Avoid eval on dynamic input; use a safe dispatch table or whitelist of allowed operations.
SHIELD-RUBY-012criticalCWE-502Unsafe deserialization via Marshal.loadDetects Marshal.load on untrusted data which can instantiate arbitrary objects and execute code.
Ruby files via Marshal.load pattern matching
Never deserialize untrusted data with Marshal; use JSON with a strict schema instead.
SHIELD-RUBY-013criticalCWE-502Unsafe deserialization via YAML.load or Oj object modeDetects YAML.load or Oj.load in object mode on untrusted input instantiating arbitrary Ruby objects.
Ruby files via YAML.load/Oj pattern matching
Use YAML.safe_load or Oj with :strict mode to reject arbitrary object instantiation.
SHIELD-RUST-001criticalCWE-89SQL injection via format! in queryDetects SQL query/execute methods called with format! string interpolation.
Rust files via query/execute + format! pattern matching
Use parameterized queries with bind parameters instead of building SQL via format!.
SHIELD-RUST-002criticalCWE-89SQL injection via diesel sql_query with format!Detects diesel::sql_query built from format! interpolating untrusted values into raw SQL.
Rust files via sql_query + format! pattern matching
Bind parameters with .bind() rather than interpolating into the SQL string.
SHIELD-RUST-004criticalCWE-78Command injection via interpolated argumentDetects process argument passed via .arg() with format! allowing command injection.
Rust files via .arg + format! pattern matching
Pass fixed arguments as separate .arg() values; never build args from untrusted input.
SHIELD-RUST-005criticalCWE-78Command execution via shell interpreterDetects Command::new spawning a shell (sh/bash/cmd/powershell/zsh) enabling command injection.
Rust files via Command::new + shell pattern matching
Invoke the target binary directly with argument vectors instead of a shell.
SHIELD-RUST-013criticalCWE-295TLS certificate verification disabledDetects danger_accept_invalid_certs/hostnames enabled disabling TLS validation.
Rust files via danger_accept_invalid pattern matching
Never disable certificate or hostname verification in production TLS clients.
SHIELD-SWIFT-001criticalCWE-89SQL injection via string interpolationDetects SQLite query built with Swift string interpolation via \() syntax.
Swift files via sqlite3_exec + string interpolation pattern matching
Use sqlite3_prepare_v2 with bound parameters via sqlite3_bind_* instead of interpolating values.
SHIELD-SWIFT-002criticalCWE-89SQL injection via string concatenationDetects raw SQL query assembled with the concatenation operator + on variable input.
Swift files via SQL + concatenation pattern matching
Use parameterized queries with bound placeholders rather than concatenating strings.
SHIELD-SWIFT-003criticalCWE-78Command injection via Process argumentsDetects Process/NSTask launched with arguments derived from variable interpolation.
Swift files via Process.arguments + interpolation pattern matching
Avoid shell interpolation and pass fixed argument arrays with validated inputs.
SHIELD-SWIFT-004criticalCWE-78Command injection via system callDetects shell command executed through system() or popen with interpolated data.
Swift files via system/popen + interpolation pattern matching
Do not pass user data to a shell; use Process with an explicit argument array.
SHIELD-SWIFT-010criticalCWE-295Insecure TLS trust bypassDetects URLSession delegate returning a credential from serverTrust without validation.
Swift files via URLCredential(trust:) pattern matching
Validate the server trust with SecTrustEvaluateWithError or pinning before accepting.
SHIELD-CPP-001highCWE-120Unbounded strcpy buffer overflowDetects strcpy() which copies without a length limit and can overflow the destination buffer.
C/C++ files via strcpy() pattern matching
Use strncpy or strlcpy with an explicit bounded size and ensure null termination.
SHIELD-CPP-002highCWE-120Unbounded strcat buffer overflowDetects strcat() which appends without checking remaining destination capacity.
C/C++ files via strcat() pattern matching
Use strncat or strlcat with the remaining buffer size accounted for.
SHIELD-CPP-003highCWE-120Unbounded sprintf buffer overflowDetects sprintf() or vsprintf() which write formatted output without a size limit.
C/C++ files via sprintf/vsprintf pattern matching
Use snprintf or vsnprintf with an explicit buffer size.
SHIELD-CPP-005highCWE-120Unbounded scanf %s readDetects scanf() with %s format specifier which reads into a buffer without a width limit.
C/C++ files via scanf + %s pattern matching
Specify a maximum field width such as %31s matching the buffer size.
SHIELD-CPP-006highCWE-134Non-constant format stringDetects printf/vprintf called with a variable format string enabling format string attacks.
C/C++ files via printf + variable format pattern matching
Always pass a constant format string such as printf("%s", var).
SHIELD-CPP-007highCWE-134Non-constant format string with stream targetDetects fprintf/sprintf using a variable as the format argument enabling format string attacks.
C/C++ files via fprintf/sprintf + variable format pattern matching
Pass an explicit constant format string instead of a variable.
SHIELD-CPP-010highCWE-78Exec with untrusted pathDetects execl/execlp invoked with a variable program path allowing execution of attacker binaries.
C/C++ files via exec + variable path pattern matching
Use absolute trusted paths and validate arguments before calling exec.
SHIELD-CPP-013highCWE-327Weak cryptographic primitiveDetects use of DES, MD5, or SHA1 which provides broken or deprecated cryptographic strength.
C/C++ files via weak crypto pattern matching
Use AES-GCM for encryption and SHA-256 or stronger for hashing.
SHIELD-CPP-014highCWE-327Insecure ECB cipher modeDetects EVP_*_ecb cipher mode usage which leaks plaintext structure and is not semantically secure.
C/C++ files via ECB cipher pattern matching
Use an authenticated mode such as GCM with a unique nonce per message.
SHIELD-CPP-015highCWE-798Hardcoded credential literalDetects PASS, PASSWORD, SECRET, or APIKEY constants assigned string literals.
C/C++ files via hardcoded credential pattern matching
Load secrets from environment variables or a secrets manager at runtime.
SHIELD-CPP-019highCWE-120memcpy with unchecked lengthDetects memcpy/memmove with a variable length from input which can overflow the destination buffer.
C/C++ files via memcpy/memmove + variable length pattern matching
Validate the length against the destination capacity before copying.
SHIELD-CPP-021highCWE-338Insecure random for security tokensDetects rand/random/srand usage for security-sensitive values which is not cryptographically secure.
C/C++ files via insecure random pattern matching
Use a CSPRNG such as getrandom or RAND_bytes for security-sensitive values.
SHIELD-CSHARP-005highCWE-78Command injection via ProcessStartInfo.Arguments from variableDetects ProcessStartInfo.Arguments assigned a value derived from concatenation or a raw variable.
C# files via ProcessStartInfo.Arguments + variable pattern matching
Use ArgumentList with individually validated arguments instead of building a single Arguments string.
SHIELD-CSHARP-008highCWE-502Insecure deserialization via JavaScriptSerializer SimpleTypeResolverDetects JavaScriptSerializer constructed with a SimpleTypeResolver permitting arbitrary type deserialization.
C# files via JavaScriptSerializer + SimpleTypeResolver pattern matching
Construct JavaScriptSerializer without a type resolver or migrate to System.Text.Json.
SHIELD-CSHARP-009highCWE-611XXE via unsafe DtdProcessing or XmlResolverDetects XML reader with DtdProcessing.Parse or XmlResolver assignment exposing parser to XXE attacks.
C# files via unsafe XML configuration pattern matching
Set DtdProcessing to Prohibit and XmlResolver to null when parsing untrusted XML.
SHIELD-CSHARP-010highCWE-611XXE via XmlTextReader without resolver hardeningDetects XmlTextReader created from a variable source without disabling DTD processing.
C# files via XmlTextReader + variable pattern matching
Use XmlReader.Create with XmlReaderSettings that set DtdProcessing to Prohibit and XmlResolver to null.
SHIELD-CSHARP-011highCWE-327Weak or broken cryptographic algorithmDetects instantiation of weak ciphers (DES, TripleDES, RC2) or hashes (MD5, SHA1) for security use.
C# files via weak crypto algorithm pattern matching
Use AES with an authenticated mode for encryption and SHA-256 or stronger for hashing.
SHIELD-CSHARP-012highCWE-327Insecure ECB cipher modeDetects symmetric cipher configured to use ECB mode which leaks plaintext patterns.
C# files via CipherMode.ECB pattern matching
Use an authenticated mode such as GCM, or CBC with a random IV instead of ECB.
SHIELD-CSHARP-013highCWE-22Path traversal from request input into file APIDetects file read or stream opened using a path derived directly from HTTP request input.
C# files via file operation + Request pattern matching
Canonicalize and validate the path against an allowlisted base directory before opening the file.
SHIELD-CSHARP-014highCWE-918SSRF via request from variable-controlled URLDetects HTTP request target built from a variable allowing server-side request forgery.
C# files via WebRequest.Create/HttpClient + variable pattern matching
Validate the URL host against an allowlist and reject internal or link-local addresses before making the request.
SHIELD-CSHARP-015highCWE-798Hardcoded credential in sourceDetects password, pwd, or ConnectionString variables assigned literal quoted strings of 3+ characters.
C# files via hardcoded credential pattern matching
Load secrets from a secrets manager, environment variable, or protected configuration store.
SHIELD-CSHARP-017highCWE-90LDAP injection via DirectorySearcher filterDetects DirectorySearcher filter built by concatenating untrusted input into the LDAP query.
C# files via DirectorySearcher.Filter + concatenation pattern matching
Escape LDAP special characters in user input before building the search filter.
SHIELD-CSHARP-018highCWE-79Reflected XSS via Response.Write or Html.RawDetects Response.Write with HTTP request input or Html.Raw usage on user-controlled content.
C# files via Response.Write/Html.Raw + request pattern matching
HTML-encode untrusted output and avoid Html.Raw for user-controlled content.
SHIELD-CSHARP-019highCWE-295Trust-all TLS certificate validationDetects certificate validation callback overridden to always return true, disabling TLS trust checks.
C# files via certificate validation callback pattern matching
Perform proper certificate chain and hostname validation instead of returning true unconditionally.
SHIELD-CSHARP-021highCWE-470Unsafe reflection from user-controlled type nameDetects Type.GetType or Activator.CreateInstance invoked with a variable type name from untrusted input.
C# files via reflection + variable type pattern matching
Map user input to an allowlisted set of known types rather than resolving arbitrary type names.
SHIELD-DART-003highCWE-78Command injection via interpolated process argumentsDetects Process call with interpolated variable arguments manipulated to run arbitrary commands.
Dart files via Process + variable pattern matching
Validate and whitelist arguments and never pass raw user input to a process invocation.
SHIELD-DART-004highCWE-79WebView JavaScript injectionDetects evaluateJavascript/runJavascript with JavaScript built from variables enabling script injection.
Dart files via WebView JavaScript + variable pattern matching
JSON-encode values passed into WebView JavaScript and avoid injecting raw user input.
SHIELD-DART-007highCWE-327Weak cryptographic hashDetects MD5 or SHA-1 from the crypto package which are broken and unsuitable for passwords.
Dart files via weak hash pattern matching
Use SHA-256 or stronger, and bcrypt, scrypt, or Argon2 for password hashing.
SHIELD-DART-008highCWE-798Hardcoded secret credentialDetects password, apiKey, secret, or token variables assigned literal strings.
Dart files via hardcoded secret pattern matching
Load secrets from secure storage or environment configuration, never from source literals.
SHIELD-DART-009highCWE-312Sensitive data in insecure storageDetects passwords/tokens stored in SharedPreferences which saves them in plaintext.
Dart files via SharedPreferences + sensitive keyword pattern matching
Use flutter_secure_storage or the platform keystore for sensitive values.
SHIELD-DART-010highCWE-22Path traversal via unsanitized file pathDetects File constructed from request-derived input allowing path traversal.
Dart files via File + request pattern matching
Canonicalize the path and verify it stays within an allowed base directory.
SHIELD-DART-011highCWE-918SSRF via user-controlled request URLDetects http HTTP methods with variable URLs letting attackers force requests to internal services.
Dart files via http + Uri.parse + variable pattern matching
Validate the URL against an allowlist of trusted hosts before making the request.
SHIELD-DART-014highCWE-749WebView with unrestricted JavaScript modeDetects WebView using unrestricted JavaScript mode exposing loaded content to full script execution.
Dart files via JavascriptMode.unrestricted pattern matching
Disable JavaScript unless required, restrict file access, and load only trusted content.
SHIELD-GEN-005highCWE-798Generic API key or secret patternMatches patterns where api_key, api_secret, client_secret, or access_token are assigned values of 20+ alphanumeric characters.
All languages via assignment pattern matching
Move secrets to environment variables or a secrets manager.
SHIELD-GEN-007highCWE-798Slack webhook URL exposedMatches Slack webhook URL pattern (hooks.slack.com/services/...) which allows posting messages to channels without authentication.
All languages via Slack webhook pattern matching
Revoke and rotate the Slack webhook URL. Store it in an environment variable.
SHIELD-GEN-009highCWE-798Database password hardcoded in connection stringMatches database connection string patterns (postgres://, mysql://, mongodb://, redis://) with embedded username:password credentials.
All languages via connection string pattern matching
Use environment variables for database connection strings. Never commit credentials.
SHIELD-GO-003highCWE-327Weak cryptographic hash (MD5)Detects md5.New() or md5.Sum() calls which are cryptographically broken.
Go files via md5 pattern matching
Use crypto/sha256 or crypto/sha512 instead of crypto/md5.
SHIELD-GO-004highCWE-327Weak cryptographic hash (SHA1)Detects sha1.New() or sha1.Sum() calls which are cryptographically weak.
Go files via sha1 pattern matching
Use crypto/sha256 or crypto/sha512 instead of crypto/sha1.
SHIELD-GO-006highCWE-22Path traversal via user-controlled filepathDetects file operations (os.Open, Create, ReadFile, WriteFile) with user input from HTTP request.
Go files via file operation + request pattern matching
Use filepath.Clean() and verify the path is within the allowed base directory.
SHIELD-GO-008highCWE-295TLS InsecureSkipVerify enabledDetects InsecureSkipVerify: true in TLS configuration which disables certificate validation.
Go files via InsecureSkipVerify: true pattern matching
Never set InsecureSkipVerify to true in production. Fix the TLS certificate instead.
SHIELD-GO-009highCWE-798Hardcoded password or secretDetects password, secret, apiKey, token, or passwd variables assigned quoted strings of 8+ characters.
Go files via hardcoded credential pattern matching
Use environment variables or a secrets manager instead of hardcoded credentials.
SHIELD-GO-010highCWE-918Server-Side Request Forgery via http.Get with user inputDetects http.Get, http.Post, or http.Do with user-controlled URLs from request.
Go files via http method + request pattern matching
Validate URLs against an allowlist before making outbound HTTP requests.
SHIELD-JAVA-006highCWE-611XXE via DocumentBuilderFactoryDetects DocumentBuilderFactory.newInstance() without disabling external entities.
Java files via DocumentBuilderFactory pattern matching
Call setFeature to disable doctype declarations and external general and parameter entities.
SHIELD-JAVA-007highCWE-611XXE via SAXParserFactoryDetects SAXParserFactory.newInstance() without disabling external entities.
Java files via SAXParserFactory pattern matching
Disable external entities and DTDs via setFeature before parsing untrusted XML.
SHIELD-JAVA-008highCWE-327Weak Cipher AlgorithmDetects Cipher.getInstance() using DES, RC4, or ECB mode which provides inadequate confidentiality.
Java files via Cipher weak algorithm pattern matching
Use AES in GCM or another authenticated mode with a securely managed key.
SHIELD-JAVA-010highCWE-798Hardcoded CredentialsDetects password, secret, apikey, or token variables assigned string literals.
Java files via hardcoded credential pattern matching
Load secrets from environment variables or a secrets manager, never from source code.
SHIELD-JAVA-011highCWE-22Path Traversal via File ConstructionDetects File constructor with request-derived input (request, getParameter, params, userInput) without validation.
Java files via File + request pattern matching
Canonicalize the path and verify it stays within an allowed base directory.
SHIELD-JAVA-012highCWE-918SSRF via URL openConnectionDetects new URL(variable).openConnection() which allows SSRF attacks.
Java files via URL.openConnection + variable pattern matching
Validate the target against an allowlist of permitted hosts and protocols before connecting.
SHIELD-JAVA-013highCWE-90LDAP Injection via Concatenated FilterDetects LDAP search filter built with string concatenation which permits LDAP injection.
Java files via LDAP search + concatenation pattern matching
Escape LDAP special characters or use parameterized search with encoded filter values.
SHIELD-JAVA-016highCWE-470Unsafe Reflection via Class.forName with VariableDetects Class.forName() loading a class from a variable enabling attacker-controlled class loading.
Java files via Class.forName + variable pattern matching
Restrict loadable classes to an allowlist rather than instantiating from raw input.
SHIELD-JS-003highCWE-79Cross-Site Scripting (XSS) via innerHTMLDetects .innerHTML assignment which can inject unescaped HTML when used with user-controlled data.
JavaScript/TypeScript files via .innerHTML pattern matching
Use textContent or sanitize input with a library like DOMPurify before setting innerHTML.
SHIELD-JS-004highCWE-79Cross-Site Scripting (XSS) via document.writeDetects document.write() calls which can inject user input directly into the DOM.
JavaScript/TypeScript files via document.write pattern matching
Avoid document.write; use DOM manipulation methods instead.
SHIELD-JS-006highCWE-95Dangerous Function() constructorDetects new Function() which dynamically compiles code and is equivalent to eval().
JavaScript/TypeScript files via Function constructor pattern matching
Avoid the Function constructor. Refactor to static functions.
SHIELD-JS-007highCWE-1321Prototype pollution via merge/assignDetects patterns accessing __proto__, constructor.prototype, or prototype.__proto__ in merge operations.
JavaScript/TypeScript files via prototype pollution pattern matching
Sanitize object keys before merging. Use Object.create(null) for dictionaries.
SHIELD-JS-008highCWE-22Path traversal via user inputDetects file read/write methods (readFile, createReadStream, writeFile) called with request.params/query/body.
JavaScript/TypeScript files via file method + request pattern matching
Validate and sanitize file paths. Use path.resolve() and check against an allowed base directory.
SHIELD-JS-011highCWE-798Hardcoded password or secretDetects password, secret, apikey, token, or passwd variables assigned quoted strings of 8+ characters.
JavaScript/TypeScript files via hardcoded credential pattern matching
Store secrets in environment variables or a secrets manager. Never hardcode credentials.
SHIELD-JS-014highCWE-295Disabled TLS/SSL certificate verificationDetects rejectUnauthorized: false configuration which disables certificate verification.
JavaScript/TypeScript files via rejectUnauthorized: false pattern
Never disable certificate verification in production. Fix the certificate instead.
SHIELD-JS-016highCWE-918Server-Side Request Forgery (SSRF) via user-controlled URLDetects fetch, axios, or http methods called with request.params/query/body allowing SSRF attacks.
JavaScript/TypeScript files via fetch/axios + request pattern matching
Validate and allowlist URLs before making server-side HTTP requests.
SHIELD-KOTLIN-005highCWE-749WebView addJavascriptInterface exposes native code to JSDetects WebView.addJavascriptInterface bridging JavaScript to native objects enabling remote code execution.
Kotlin files via addJavascriptInterface pattern matching
Avoid addJavascriptInterface for untrusted content; if required, target API 17+ and annotate exposed methods with @JavascriptInterface.
SHIELD-KOTLIN-006highCWE-79JavaScript injection via WebView loadUrl/evaluateJavascriptDetects concatenating or interpolating a variable into WebView loadUrl('javascript:') or evaluateJavascript.
Kotlin files via WebView JavaScript + variable pattern matching
Never inject untrusted data into JavaScript; encode values or pass them via safe message channels.
SHIELD-KOTLIN-008highCWE-327Weak or ECB-mode cipher via Cipher.getInstanceDetects Cipher requesting DES, RC4, or AES in ECB mode providing inadequate confidentiality.
Kotlin files via Cipher weak algorithm/mode pattern matching
Use AES in GCM mode (AES/GCM/NoPadding) with a securely generated random IV.
SHIELD-KOTLIN-010highCWE-798Hardcoded secret in sourceDetects password, api_key, secret, token, or access_key variable assigned a literal string constant.
Kotlin files via hardcoded secret pattern matching
Load secrets from the Android Keystore, encrypted storage, or a secure server-side configuration.
SHIELD-KOTLIN-011highCWE-22Path traversal via File/FileInputStream with request inputDetects File/FileInputStream constructed from request-derived input allowing path traversal.
Kotlin files via File + request pattern matching
Canonicalize the path and verify it stays within an allowed base directory before opening.
SHIELD-KOTLIN-012highCWE-918SSRF via URL(variable).openConnectionDetects URL constructor with variable enabling SSRF attacks to internal services.
Kotlin files via URL + variable pattern matching
Validate the target host against an allowlist and reject internal or link-local addresses.
SHIELD-KOTLIN-015highCWE-732World-readable or world-writable file modeDetects MODE_WORLD_READABLE or MODE_WORLD_WRITEABLE exposing app files to other applications.
Kotlin files via MODE_WORLD pattern matching
Use MODE_PRIVATE and store sensitive data with EncryptedSharedPreferences or the Keystore.
SHIELD-KOTLIN-017highCWE-312Password stored in plaintext SharedPreferencesDetects password/token/secret written into standard SharedPreferences stored unencrypted.
Kotlin files via SharedPreferences + sensitive keyword pattern matching
Use EncryptedSharedPreferences (Jetpack Security) or the Android Keystore for sensitive values.
SHIELD-KOTLIN-018highCWE-749WebView JavaScript enabled with file accessDetects WebView with JavaScript and file access enabled allowing local file exfiltration.
Kotlin files via WebView JavaScript + file access pattern matching
Disable file access for WebViews that render remote content and only enable JavaScript when strictly required.
SHIELD-PHP-008highCWE-79Reflected XSS via echo of request dataDetects request superglobal echoed or printed without output encoding enabling cross-site scripting.
PHP files via echo/print + request superglobal pattern matching
Encode output with htmlspecialchars() using ENT_QUOTES before echoing user input.
SHIELD-PHP-010highCWE-22Path traversal via file read with request dataDetects file read functions receiving request data directly allowing path traversal.
PHP files via file read + request superglobal pattern matching
Canonicalize with realpath() and confirm the path stays within an allowed base directory.
SHIELD-PHP-011highCWE-918Server-side request forgery via dynamic URLDetects curl target or file_get_contents URL built from a variable enabling SSRF.
PHP files via curl/file_get_contents + variable pattern matching
Validate and allowlist destination hosts; reject internal/link-local addresses.
SHIELD-PHP-012highCWE-916Weak hashing algorithm for passwordsDetects md5 or sha1 used to hash sensitive password values which are cryptographically weak.
PHP files via weak hash + password pattern matching
Use password_hash() with PASSWORD_DEFAULT and verify with password_verify().
SHIELD-PHP-013highCWE-327Insecure legacy encryption (mcrypt DES/ECB)Detects deprecated mcrypt with DES or ECB mode which provides weak, insecure encryption.
PHP files via mcrypt pattern matching
Use openssl or sodium with AES-GCM or a modern authenticated cipher.
SHIELD-PHP-014highCWE-798Hardcoded credentials in sourceDetects password, pwd, db_pass, secret, or api_key constants assigned literal strings.
PHP files via hardcoded credential pattern matching
Load credentials from environment variables or a secrets manager, not from source.
SHIELD-PHP-016highCWE-697Type juggling in loose comparison of hashesDetects loose == comparison against hash function result enabling type juggling authentication bypass.
PHP files via hash comparison pattern matching
Use strict === comparison or hash_equals() for constant-time hash comparison.
SHIELD-PHP-018highCWE-621Variable overwrite via extract on request dataDetects extract() applied to request superglobals allowing attackers to overwrite arbitrary local variables.
PHP files via extract + request superglobal pattern matching
Avoid extract() on user input; access specific request keys explicitly.
SHIELD-PY-006highCWE-78Shell injection via subprocess with shell=TrueDetects subprocess calls (run, Popen, call, check_output) with shell=True parameter.
Python files via subprocess + shell=True pattern matching
Use shell=False (default) and pass arguments as a list to avoid shell injection.
SHIELD-PY-007highCWE-918Server-Side Request Forgery (SSRF) via requests with user inputDetects requests HTTP methods called with request.args/form/json/data/values.
Python files via requests + request pattern matching
Validate and allowlist URLs before making outbound HTTP requests.
SHIELD-PY-009highCWE-22Path traversal via open()Detects open() calls with user-controlled paths from request.args/form/json/values.
Python files via open + request pattern matching
Validate file paths using os.path.realpath() and check against an allowed base directory.
SHIELD-PY-011highCWE-798Hardcoded password or secretDetects PASSWORD, SECRET, API_KEY, TOKEN, or PASSWD constants assigned quoted strings of 8+ characters.
Python files via hardcoded credential pattern matching
Store secrets in environment variables or a secrets manager. Never hardcode credentials.
SHIELD-PY-012highCWE-94Flask debug mode enabledDetects app.run() with debug=True parameter which enables interactive debugger in production.
Python files via Flask debug=True pattern matching
Disable debug mode in production. Use environment variables to control debug settings.
SHIELD-PY-013highCWE-502YAML deserialization with yaml.load (unsafe)Detects yaml.load() without Loader parameter which can deserialize arbitrary Python objects.
Python files via yaml.load pattern matching
Use yaml.safe_load() instead of yaml.load() to prevent arbitrary object deserialization.
SHIELD-PY-015highCWE-611XML External Entity (XXE) injectionDetects XML parsing via xml.etree.ElementTree or lxml.etree without disabling external entities.
Python files via XML parsing pattern matching
Disable external entity processing. Use defusedxml library for safe XML parsing.
SHIELD-PY-016highCWE-502Insecure deserialization with marshalDetects marshal.loads() or marshal.load() which can cause crashes or arbitrary code execution.
Python files via marshal deserialization pattern matching
Do not deserialize untrusted data with marshal. Use JSON for data interchange.
SHIELD-RUBY-006highCWE-78Command injection via Open3 or spawn with variableDetects single interpolated string passed to Open3/spawn which invokes a shell and permits injection.
Ruby files via Open3/spawn + interpolation pattern matching
Provide the command and each argument as distinct array elements to Open3 or spawn.
SHIELD-RUBY-008highCWE-95Code injection via instance_eval or class_evalDetects instance_eval/class_eval on dynamic input executing arbitrary code in an object or class context.
Ruby files via instance_eval/class_eval + dynamic input pattern matching
Do not evaluate user-supplied strings; refactor to call known methods directly.
SHIELD-RUBY-009highCWE-94Unsafe method dispatch via send with user inputDetects send/public_send called with a params-derived method name allowing arbitrary method invocation.
Ruby files via send + params pattern matching
Whitelist allowed method names before dispatching with send.
SHIELD-RUBY-010highCWE-915Mass assignment via permit bangDetects permit! call which bypasses strong parameter filtering allowing assignment of any attribute.
Ruby files via permit! pattern matching
Explicitly permit only the required attributes with permit(:a, :b).
SHIELD-RUBY-011highCWE-915Mass assignment via update with raw paramsDetects unfiltered params passed directly to update/assign_attributes allowing mass assignment.
Ruby files via update + params pattern matching
Filter params through strong parameters before passing them to update.
SHIELD-RUBY-014highCWE-918SSRF via open-uri or Net::HTTP with variable URLDetects URI.open/Net::HTTP.get with user input or interpolated URL allowing server-side request forgery.
Ruby files via open-uri/Net::HTTP + variable URL pattern matching
Validate the URL against an allowlist of hosts and schemes before fetching.
SHIELD-RUBY-015highCWE-22Path traversal via File or send_file with paramsDetects file path built from params in File.read/File.open/send_file enabling path traversal.
Ruby files via file operation + params pattern matching
Resolve the path and confirm it stays within an allowed base directory before access.
SHIELD-RUBY-016highCWE-79XSS via raw or html_safe on dynamic dataDetects raw() or .html_safe on interpolated/variable content outputting unescaped HTML.
Ruby files via raw/html_safe + dynamic data pattern matching
Let Rails auto-escape output or sanitize with the sanitize helper instead of raw or html_safe.
SHIELD-RUBY-017highCWE-79XSS via unescaped ERB output tagDetects <%== unescaped ERB output tag which renders content without HTML escaping.
Ruby files via <%== pattern matching
Use the escaping ERB tag and only bypass escaping for content you fully control.
SHIELD-RUBY-019highCWE-798Hardcoded secret or passwordDetects password, secret_key, api_key, secret_token, or access_key assigned literal values.
Ruby files via hardcoded secret pattern matching
Load secrets from environment variables or Rails encrypted credentials.
SHIELD-RUBY-022highCWE-470Remote code execution via constantize with user inputDetects constantize/qualified_const_get on params instantiating unintended classes.
Ruby files via constantize + params pattern matching
Map user input to allowed classes through an explicit whitelist rather than constantize.
SHIELD-RUST-003highCWE-89SQL injection via string concatenationDetects SQL query methods called with + operator concatenating variables.
Rust files via query/execute + concatenation pattern matching
Use bound parameters instead of concatenating query fragments.
SHIELD-RUST-008highCWE-327Weak cryptographic hashDetects MD5/SHA-1/DES usage which are cryptographically broken and unsuitable for security.
Rust files via weak hash pattern matching
Use SHA-256+ for hashing and Argon2/bcrypt/scrypt for passwords.
SHIELD-RUST-009highCWE-798Hardcoded credentialDetects password, secret, api_key, or token variable assigned a quoted string literal.
Rust files via hardcoded credential pattern matching
Load secrets from environment variables or a secrets manager, never from source.
SHIELD-RUST-011highCWE-918SSRF via user-controlled request URLDetects reqwest/http methods called with format! URL allowing SSRF to internal hosts.
Rust files via HTTP method + format! URL pattern matching
Validate the URL against an allowlist of hosts and block private/link-local ranges.
SHIELD-RUST-012highCWE-22Path traversal via user-controlled file pathDetects File operations called with format! path enabling directory traversal.
Rust files via file operation + format! path pattern matching
Canonicalize the path and verify it stays within an allowed base directory.
SHIELD-RUST-015highCWE-89SQL statement built with format!Detects SQL query assembled with format! which interpolates values into the statement.
Rust files via format! SQL pattern matching
Build queries with bound parameters instead of format!; never interpolate values into SQL text.
SHIELD-SWIFT-005highCWE-79WebView JavaScript injectionDetects evaluateJavaScript called with a string containing interpolated variable data.
Swift files via evaluateJavaScript + interpolation pattern matching
Pass data via WKScriptMessageHandler or JSON-encode and escape values before injection.
SHIELD-SWIFT-006highCWE-79WebView HTML injection via loadHTMLStringDetects loadHTMLString rendering HTML built from interpolated variable data.
Swift files via loadHTMLString + interpolation pattern matching
Sanitize and HTML-encode user data before embedding it into loaded markup.
SHIELD-SWIFT-007highCWE-327Weak hash for passwordDetects MD5 or SHA1 used to hash passwords which is cryptographically broken.
Swift files via weak hash pattern matching
Use a memory-hard KDF such as Argon2, scrypt, or PBKDF2 with a salt for passwords.
SHIELD-SWIFT-008highCWE-327Insecure DES or ECB cipherDetects DES algorithm or ECB mode usage which are both insecure.
Swift files via weak cipher algorithm/mode pattern matching
Use AES-GCM or another authenticated cipher with a secure mode instead of DES or ECB.
SHIELD-SWIFT-009highCWE-798Hardcoded secret in sourceDetects password, api_key, secret, token, or access_key variable assigned a hardcoded string literal.
Swift files via hardcoded secret pattern matching
Load secrets from the Keychain or a secure configuration service, never from source.
SHIELD-SWIFT-011highCWE-319Arbitrary insecure HTTP loads allowedDetects App Transport Security disabled via NSAllowsArbitraryLoads or insecure HTTP exceptions.
Swift files via ATS exception pattern matching
Remove the ATS exception and require HTTPS with valid certificates for all endpoints.
SHIELD-SWIFT-012highCWE-922Sensitive data stored in UserDefaultsDetects password or token persisted in UserDefaults which is unencrypted.
Swift files via UserDefaults + sensitive keyword pattern matching
Store credentials in the Keychain with an appropriate accessibility class instead of UserDefaults.
SHIELD-SWIFT-013highCWE-22Path traversal via file readDetects file read from a path built with interpolated variable data.
Swift files via Data(contentsOf:URL) + interpolation pattern matching
Canonicalize the path and confine it to an allowed base directory before reading.
SHIELD-SWIFT-014highCWE-918SSRF via dynamic URL requestDetects URLSession request targeting a URL constructed from variable input.
Swift files via URL + variable pattern matching
Validate the host against an allowlist before issuing outbound requests.
SHIELD-SWIFT-015highCWE-338Insecure random for security tokenDetects arc4random or non-cryptographic random source used to generate a token.
Swift files via insecure random + token pattern matching
Generate security tokens with SecRandomCopyBytes for cryptographic strength.
SHIELD-CPP-011mediumCWE-190Integer overflow in malloc sizeDetects malloc/calloc/realloc with a multiplied size which can overflow and allocate too little.
C/C++ files via allocation + multiplication pattern matching
Use calloc or check for multiplication overflow before allocating.
SHIELD-CPP-012mediumCWE-770Dangerous alloca or VLA with variable sizeDetects alloca() with a variable size which can exhaust the stack and cause overflow.
C/C++ files via alloca + variable size pattern matching
Use heap allocation with a validated bounded size instead of alloca.
SHIELD-CPP-016mediumCWE-377Insecure temporary file creationDetects mktemp/tmpnam/tempnam calls which generate predictable names vulnerable to symlink attacks.
C/C++ files via insecure temp pattern matching
Use mkstemp which atomically creates and opens a unique file.
SHIELD-CPP-017mediumCWE-22File open with untrusted pathDetects fopen/open with a variable path allowing path traversal to unintended files.
C/C++ files via file open + variable path pattern matching
Canonicalize the path with realpath and confirm it stays inside an allowed directory.
SHIELD-CPP-018mediumCWE-367TOCTOU race with access then openDetects access() call which creates a time-of-check to time-of-use race condition.
C/C++ files via access() pattern matching
Open the file first and check permissions on the resulting descriptor with fstat.
SHIELD-CPP-020mediumCWE-170strncpy without null terminationDetects strncpy() calls which may leave the destination without a null terminator.
C/C++ files via strncpy pattern matching
Explicitly set the final byte to zero or use strlcpy.
SHIELD-CSHARP-016mediumCWE-338Insecure random used for security tokensDetects System.Random usage with Next/NextBytes/NextDouble for security tokens.
C# files via Random pattern matching
Use RandomNumberGenerator or RNGCryptoServiceProvider for security-sensitive random values.
SHIELD-CSHARP-020mediumCWE-601Open redirect from request inputDetects Response.Redirect targeting a URL taken directly from HTTP request input.
C# files via Response.Redirect + request pattern matching
Validate redirect targets against an allowlist of trusted local paths or hosts.
SHIELD-DART-006mediumCWE-319Insecure cleartext HTTP endpointDetects cleartext http:// URLs which transmit data without encryption.
Dart files via http:// pattern matching
Use HTTPS endpoints and enforce TLS for all network requests.
SHIELD-DART-012mediumCWE-338Insecure random for security tokensDetects Random() usage which is not cryptographically secure for tokens or secrets.
Dart files via Random pattern matching
Use Random.secure() for any security-sensitive random value.
SHIELD-DART-013mediumCWE-532Sensitive data logged to consoleDetects print/debugPrint/log statements leaking passwords or tokens into device logs.
Dart files via logging + sensitive keyword pattern matching
Remove secrets from log output or redact them before logging.
SHIELD-GEN-001mediumCWE-284Hardcoded IP addressDetects hardcoded IP addresses in source code which can expose internal network topology and reduce flexibility.
All languages via regex pattern matching for IPv4 addresses
Use configuration files or environment variables instead of hardcoded IP addresses.
SHIELD-GEN-010mediumCWE-295Disabled SSL/TLS verify in curl commandDetects curl usage with -k or --insecure flags which disable certificate validation, enabling MITM attacks.
All languages via curl flag pattern matching
Remove -k/--insecure from curl commands. Fix the TLS certificate instead.
SHIELD-GO-005mediumCWE-338Insecure random number generation via math/randDetects math/rand functions (Intn, Int63, Float64, New, Seed) which are not cryptographically secure.
Go files via math/rand pattern matching
Use crypto/rand for security-sensitive randomness.
SHIELD-GO-011mediumCWE-601Open redirect via http.Redirect with user inputDetects http.Redirect called with user input from request URL, Form, PostForm, or Header.
Go files via http.Redirect + request pattern matching
Validate redirect targets against an allowlist of permitted URLs.
SHIELD-JAVA-009mediumCWE-327Weak Hash AlgorithmDetects MessageDigest.getInstance() using MD5 or SHA-1 which are cryptographically broken.
Java files via MessageDigest weak algorithm pattern matching
Use SHA-256 or stronger; for passwords use bcrypt, scrypt, or Argon2.
SHIELD-JAVA-015mediumCWE-330Insecure Randomness for Security TokensDetects new Random() usage for security tokens yielding predictable values.
Java files via Random constructor pattern matching
Use java.security.SecureRandom for tokens, session IDs, and any security-sensitive values.
SHIELD-JS-010mediumCWE-338Insecure random number generationDetects Math.random() usage which is not cryptographically secure for security-sensitive operations.
JavaScript/TypeScript files via Math.random() pattern matching
Use crypto.getRandomValues() or crypto.randomBytes() for security-sensitive randomness.
SHIELD-JS-012mediumCWE-319Insecure HTTP usage (non-HTTPS)Detects http:// URLs in code which expose data to interception.
JavaScript/TypeScript files via http:// pattern matching
Use HTTPS for all external connections.
SHIELD-JS-013mediumCWE-601Open redirect via res.redirectDetects res.redirect() called with request.params/query/body which can redirect to attacker-controlled URLs.
JavaScript/TypeScript files via res.redirect + request pattern matching
Validate redirect URLs against an allowlist of trusted destinations.
SHIELD-JS-015mediumCWE-532Sensitive data in console.logDetects console logging statements (log, info, debug, warn) containing password, token, secret, or apikey keywords.
JavaScript/TypeScript files via console logging + sensitive keyword pattern matching
Remove sensitive data from log statements. Use structured logging with redaction.
SHIELD-JS-017mediumCWE-1333Regex Denial of Service (ReDoS) — catastrophic backtrackingDetects new RegExp() constructed from request.params/query/body which can cause exponential backtracking.
JavaScript/TypeScript files via RegExp + request pattern matching
Never construct regexes from user input. Use a safe regex library or validate input first.
SHIELD-KOTLIN-009mediumCWE-327Weak hash algorithm via MessageDigest.getInstanceDetects MessageDigest with MD5 or SHA-1 which are cryptographically broken.
Kotlin files via MessageDigest weak algorithm pattern matching
Use SHA-256 or stronger, and for passwords use a KDF such as bcrypt, scrypt, or PBKDF2.
SHIELD-KOTLIN-013mediumCWE-338Insecure random used for security tokensDetects java.util.Random or kotlin.random.Random usage which is predictable for tokens.
Kotlin files via insecure random pattern matching
Use java.security.SecureRandom for any security-sensitive random values.
SHIELD-KOTLIN-016mediumCWE-532Sensitive data logged via Log statementsDetects Log.d/Log.e/Log.i statements leaking passwords/tokens/secrets into device logs.
Kotlin files via Log + sensitive keyword pattern matching
Never log secrets; redact sensitive fields and disable verbose logging in release builds.
SHIELD-PHP-015mediumCWE-338Insecure randomness for security tokensDetects rand/mt_rand/uniqid/lcg_value used to generate token, secret, nonce, or key.
PHP files via insecure random pattern matching
Use random_bytes() or random_int() for cryptographically secure token generation.
SHIELD-PHP-017mediumCWE-113HTTP header injection via dynamic header valueDetects header() function called with a variable value allowing response splitting or header injection.
PHP files via header + variable pattern matching
Validate header values and strip CR/LF characters before calling header().
SHIELD-PY-010mediumCWE-327Weak MD5 or SHA1 hash usageDetects hashlib.md5() or hashlib.sha1() usage which are cryptographically broken.
Python files via weak hash pattern matching
Use hashlib.sha256() or hashlib.sha3_256() instead.
SHIELD-PY-014mediumCWE-338Insecure random number for security purposesDetects random module functions (random, randint, choice, shuffle, sample) which are not cryptographically secure.
Python files via random module pattern matching
Use secrets module (secrets.token_bytes, secrets.choice) for security-sensitive randomness.
SHIELD-PY-017mediumCWE-208Timing attack in string comparisonDetects password, token, secret, key, or signature variables compared with == operator which is vulnerable to timing attacks.
Python files via timing attack pattern matching
Use hmac.compare_digest() for constant-time string comparison of secrets.
SHIELD-RUBY-018mediumCWE-327Weak hashing with MD5 or SHA1Detects Digest::MD5 or Digest::SHA1 usage for passwords or integrity which is cryptographically broken.
Ruby files via Digest weak hash pattern matching
Use bcrypt or Argon2 for passwords and SHA-256 or stronger for integrity.
SHIELD-RUBY-020mediumCWE-330Insecure randomness for tokensDetects token/secret/nonce/salt/otp assigned rand() or Random.rand/new producing predictable values.
Ruby files via insecure random pattern matching
Generate tokens with SecureRandom.hex or SecureRandom.uuid.
SHIELD-RUBY-021mediumCWE-601Open redirect via redirect_to with paramsDetects redirect_to called with params allowing attackers to send users to arbitrary sites.
Ruby files via redirect_to + params pattern matching
Redirect only to validated internal paths or set allow_other_host to false.
SHIELD-RUBY-023mediumCWE-1333Regex denial of service via interpolated patternDetects Regexp.new built from unsanitized user input creating catastrophic backtracking patterns.
Ruby files via Regexp.new + user input pattern matching
Escape user input with Regexp.escape or match against a fixed anchored pattern.
SHIELD-RUST-006mediumCWE-119Unsafe block requires reviewDetects unsafe blocks which bypass Rust memory-safety guarantees and must be manually audited.
Rust files via unsafe block pattern matching
Confirm the unsafe block upholds all invariants; prefer safe abstractions where possible.
SHIELD-RUST-007mediumCWE-502Insecure deserialization of untrusted bytesDetects bincode/rmp deserialization of attacker-controlled bytes without validation.
Rust files via bincode/rmp deserialization pattern matching
Validate and bound input, and prefer self-describing formats with strict schemas.
SHIELD-RUST-010mediumCWE-338Insecure randomness for security valueDetects rand::random or thread_rng usage which is not a CSPRNG guarantee for tokens.
Rust files via insecure random pattern matching
Use a CSPRNG (rand::rngs::OsRng / getrandom) for security-sensitive values.
SHIELD-SWIFT-016mediumCWE-200Sensitive data copied to pasteboardDetects password or secret written to the general UIPasteboard exposing it to other apps.
Swift files via UIPasteboard + sensitive keyword pattern matching
Avoid placing secrets on the shared pasteboard, or mark items as expiring and local-only.
SHIELD-SWIFT-017mediumCWE-311Keychain item without access controlDetects Keychain item added with an insecure always-accessible protection class.
Swift files via kSecAttrAccessibleAlways pattern matching
Use kSecAttrAccessibleWhenUnlockedThisDeviceOnly or add SecAccessControl with biometrics.
SHIELD-GEN-002lowCWE-1068Security-sensitive TODO/FIXME commentFinds TODO, FIXME, HACK, or XXX comments that mention security-related keywords like auth, injection, or password, indicating unresolved security debt.
All languages via comment pattern matching
Resolve the identified security issue before shipping to production.
SHIELD-GEN-011lowCWE-798Base64 encoded potential secretDetects SECRET, PASSWORD, TOKEN, or KEY variables assigned base64-encoded strings of 40+ characters, which may contain embedded secrets.
All languages via base64 pattern matching
Verify that this value does not contain a secret. Move secrets to a secrets manager.
SHIELD-GO-012lowCWE-477Use of deprecated ioutil packageDetects ioutil function usage (ReadAll, ReadFile, WriteFile, TempFile, TempDir, NopCloser, Discard) which are deprecated since Go 1.16.
Go files via ioutil pattern matching
Replace ioutil functions with their io or os equivalents (e.g., io.ReadAll, os.ReadFile).
SHIELD-RUST-014lowCWE-190Potential integer overflow in allocation sizeDetects with_capacity/Vec sizing from multiplication of untrusted values which can overflow.
Rust files via with_capacity + multiplication pattern matching
Use checked_mul and validate sizes before allocating from untrusted input.
Secrets 27 rules
SECRET-001criticalCWE-798AWS Access Key IDDetects AWS Access Key IDs matching the pattern (AKIA|ABIA|ACCA|ASIA) followed by 16 alphanumeric characters. These are the public identifiers for AWS IAM users and roles.
/opt/shield/packages/secret-detector/detector.go:29-33
Immediately rotate the exposed AWS Access Key ID. Go to AWS IAM console, delete the compromised key, create a new key pair, and update all applications and scripts using the old key. Monitor CloudTrail for unauthorized activity.
SECRET-002criticalCWE-798AWS Secret Access KeyDetects AWS Secret Access Keys through pattern matching for 'aws_secret_access_key' assignments followed by 40-character base64-like values. The secret is the private key paired with an Access Key ID.
/opt/shield/packages/secret-detector/detector.go:34-39
Immediately rotate the AWS Secret Access Key. Delete the compromised key from IAM console, create a new key pair, update all configurations and applications, and review CloudTrail logs for unauthorized access.
SECRET-003criticalCWE-798Azure Connection StringDetects Azure Storage connection strings containing DefaultEndpointsProtocol, AccountName, and AccountKey with 88-character base64-encoded key. These grant full access to Azure Storage resources.
/opt/shield/packages/secret-detector/detector.go:40-45
Revoke the compromised storage account key in Azure Portal immediately. Regenerate a new key, update all applications and services using the old key, and audit storage access logs.
SECRET-004criticalCWE-798GCP Service Account Private KeyDetects GCP Service Account JSON files containing 'private_key' field with RSA or EC private key PEM header. Service account keys grant programmatic access to GCP resources.
/opt/shield/packages/secret-detector/detector.go:46-51
Delete the compromised service account key immediately in GCP Console. Audit the service account's activity logs. Create a new key if needed and rotate it in all applications. Consider disabling the entire service account if compromise is severe.
SECRET-005criticalCWE-798GitHub Personal Access Token (classic)Detects GitHub personal access tokens (classic format) matching 'ghp_' prefix followed by 36 alphanumeric characters. These tokens grant access to GitHub repositories and user data.
/opt/shield/packages/secret-detector/detector.go:52-57
Revoke the token immediately in GitHub Settings > Developer settings > Personal access tokens. Create a new token if needed. Check GitHub audit log for any unauthorized access and rotate credentials for any secrets accessed with this token.
SECRET-006criticalCWE-798GitHub Fine-Grained Personal Access TokenDetects GitHub fine-grained personal access tokens matching 'github_pat_' prefix followed by 82 alphanumeric and underscore characters. These newer tokens offer granular permission control.
/opt/shield/packages/secret-detector/detector.go:58-63
Revoke the compromised token in GitHub Settings > Developer settings > Personal access tokens > Fine-grained tokens. Create a new token with minimal required permissions. Review GitHub audit logs for unauthorized activity.
SECRET-007criticalCWE-798GitHub OAuth App TokenDetects GitHub OAuth application tokens matching 'gho_' prefix followed by 36 alphanumeric characters. These are authorization tokens used by OAuth apps to access GitHub on behalf of users.
/opt/shield/packages/secret-detector/detector.go:64-69
Revoke the OAuth token in GitHub Settings. If the app was compromised, also revoke the entire OAuth app in GitHub Settings > Developer settings > OAuth apps. Check audit logs for unauthorized activity.
SECRET-008criticalCWE-798GitLab Personal Access TokenDetects GitLab personal access tokens matching 'glpat-' prefix followed by 20 characters of alphanumerics, hyphens, and underscores. These tokens authenticate against GitLab API and git operations.
/opt/shield/packages/secret-detector/detector.go:70-75
Revoke the token immediately in GitLab User Settings > Access Tokens. Create a new token if needed. Review GitLab audit logs to check if the token was used unauthorized. Update any CI/CD pipelines using the old token.
SECRET-010criticalCWE-798Database Connection String with CredentialsDetects database connection strings for PostgreSQL, MySQL, MongoDB, Redis, and MSSQL with embedded username and password in the connection URL (format: protocol://username:password@host).
/opt/shield/packages/secret-detector/detector.go:82-87
Change database credentials immediately. Update all applications with new credentials. Move connection strings to environment variables or secrets management systems. Audit database access logs for unauthorized queries.
SECRET-013criticalCWE-798RSA Private KeyDetects RSA private key files by matching the '-----BEGIN RSA PRIVATE KEY-----' PEM header. RSA private keys are used for authentication and encryption.
/opt/shield/packages/secret-detector/detector.go:94-99
Immediately rotate the RSA private key. Generate a new key pair and update all services using this key. Revoke the old key/certificate. If used for SSH, update authorized_keys on affected servers and audit access logs.
SECRET-014criticalCWE-798Generic Private Key (PKCS#8)Detects PKCS#8 format private keys by matching the '-----BEGIN PRIVATE KEY-----' PEM header. This format is used for various cryptographic keys including RSA, EC, and DSA.
/opt/shield/packages/secret-detector/detector.go:100-105
Immediately revoke and rotate the compromised private key. Generate a new key pair and update all systems using this key. If used for TLS/SSL, reissue certificates. If used for SSH, update authorized_keys and audit access logs.
SECRET-015criticalCWE-798OpenSSH Private KeyDetects OpenSSH format private keys by matching the '-----BEGIN OPENSSH PRIVATE KEY-----' PEM header. These are SSH keys used for authentication to servers.
/opt/shield/packages/secret-detector/detector.go:106-111
Immediately revoke the SSH key. Remove the corresponding public key from authorized_keys on all affected servers. Generate a new key pair. Audit server access logs for unauthorized logins.
SECRET-016criticalCWE-798PGP Private KeyDetects PGP private key blocks by matching the '-----BEGIN PGP PRIVATE KEY BLOCK-----' header. PGP private keys are used for encryption and digital signatures.
/opt/shield/packages/secret-detector/detector.go:112-117
Immediately revoke the PGP private key using a key revocation certificate. Upload the revocation certificate to key servers. Generate a new key pair. Notify anyone who has encrypted data to this key about the compromise.
SECRET-018criticalCWE-798Stripe Secret KeyDetects Stripe secret keys matching 'sk_live_' prefix followed by 24+ alphanumeric characters. Secret keys have full access to Stripe account and can make payments or access sensitive data.
/opt/shield/packages/secret-detector/detector.go:124-129
Revoke the compromised Stripe secret key immediately in Stripe Dashboard > API keys. Create a new secret key. Update all applications with the new key. Review Stripe API logs for unauthorized charges or access.
SECRET-019criticalCWE-798Twilio Auth TokenDetects Twilio Auth Tokens through pattern matching for 'twilio_auth_token' assignments with 32 hexadecimal characters. These tokens authenticate to Twilio API for SMS, voice, and messaging.
/opt/shield/packages/secret-detector/detector.go:130-135
Revoke the Twilio Auth Token immediately in Twilio Console > Account > Settings. Create a new auth token. Update all applications using the old token. Review Twilio usage logs for unauthorized activity.
SECRET-023criticalCWE-798OpenAI API KeyDetects OpenAI API keys matching pattern 'sk-(proj-|svcacct-|admin-)?[A-Za-z0-9_-]{20,}T3BlbkFJ[A-Za-z0-9_-]{20,}' which includes legacy and new OpenAI key formats.
/opt/shield/packages/secret-detector/detector.go:148-153
Revoke the OpenAI API key immediately in OpenAI platform account. Create a new API key with necessary scopes. Update all applications using the old key. Monitor OpenAI API usage logs for unauthorized requests.
SECRET-025criticalCWE-798Anthropic API KeyDetects Anthropic API keys matching pattern 'sk-ant-[A-Za-z0-9_-]{20,}' which is the standard format for Anthropic API authentication.
/opt/shield/packages/secret-detector/detector.go:160-165
Revoke the Anthropic API key immediately in Anthropic console. Create a new API key. Update all applications and scripts using the old key. Monitor API usage logs for unauthorized requests.
SECRET-009highCWE-798npm Access TokenDetects npm access tokens matching 'npm_' prefix followed by 36 alphanumeric characters. These tokens authenticate for npm registry operations and package publishing.
/opt/shield/packages/secret-detector/detector.go:76-81
Revoke the token immediately via 'npm token revoke' or in npmjs.com account settings. Create a new token if needed. Check npm audit logs for any unauthorized package operations. Re-authenticate for any active npm operations.
SECRET-011highCWE-798JWT Secret / Signing KeyDetects JWT signing secrets and keys assigned via patterns like 'jwt_secret' or 'jwt_signing_key' with values of 16+ characters. Compromised JWT secrets allow forging authentication tokens.
/opt/shield/packages/secret-detector/detector.go:88-93
Rotate the JWT signing secret immediately. Revoke all existing JWT tokens by invalidating them or rotating the secret on all services. Update all applications with the new secret. Force users to re-authenticate.
SECRET-012highCWE-798Generic API Key AssignmentDetects generic API key assignments through pattern matching for 'api_key' or 'apikey' with values of 20+ alphanumeric, hyphen, or underscore characters. This is a catch-all for provider-specific patterns.
/opt/shield/packages/secret-detector/detector.go:176-181
Revoke the exposed API key in the service provider's dashboard. Create a new API key with limited scopes if possible. Update applications to use the new key. Monitor for unauthorized API usage.
SECRET-017highCWE-798Slack Webhook URLDetects Slack incoming webhook URLs matching the pattern 'https://hooks.slack.com/services/T[A-Z0-9]+/B[A-Z0-9]+/[A-Za-z0-9]+'. These URLs allow posting messages to Slack channels.
/opt/shield/packages/secret-detector/detector.go:118-123
Revoke the webhook URL immediately in Slack workspace settings. Create a new webhook URL if needed. Update all applications using the old webhook. Monitor Slack for unauthorized message posting.
SECRET-020highCWE-798SendGrid API KeyDetects SendGrid API keys matching the pattern 'SG.[A-Za-z0-9\-_]{22}.[A-Za-z0-9\-_]{43}' (consists of SG. prefix, 22 chars, dot, then 43 chars). These keys authenticate to SendGrid email service.
/opt/shield/packages/secret-detector/detector.go:136-141
Revoke the SendGrid API key immediately in SendGrid Settings > API Keys. Create a new API key if needed. Update all applications and scripts using the old key. Monitor SendGrid activity logs.
SECRET-022highCWE-798Discord Bot TokenDetects Discord bot tokens matching pattern [MN][A-Za-z0-9]{23}.[\w-]{6}.[\w-]{27}. These tokens authenticate bot applications to Discord API.
/opt/shield/packages/secret-detector/detector.go:142-147
Regenerate the bot token immediately in Discord Developer Portal. Update all bot applications with the new token. Review bot audit logs for unauthorized server actions or access.
SECRET-024highCWE-798Slack TokenDetects Slack authentication tokens matching pattern 'xox[baprs]-[A-Za-z0-9-]{10,}' which covers bot (xoxb), app (xoxa), personal (xoxp), and refresh (xoxr) tokens.
/opt/shield/packages/secret-detector/detector.go:154-159
Revoke the Slack token immediately in the workspace settings. Create a new token if needed. Update all applications using the old token. Review workspace audit logs for unauthorized actions.
SECRET-026highCWE-798Linear API KeyDetects Linear API keys matching pattern 'lin_api_[A-Za-z0-9]{40}' which is the standard format for Linear API authentication.
/opt/shield/packages/secret-detector/detector.go:166-171
Revoke the Linear API key immediately in Linear workspace settings. Create a new API key if needed. Update all integrations using the old key. Review Linear audit logs for unauthorized changes.
SECRET-021mediumCWE-798Generic Password in ConfigDetects generic password assignments through pattern matching for 'password', 'passwd', or 'pwd' with quoted values of 8+ characters. This is a catch-all for hardcoded passwords.
/opt/shield/packages/secret-detector/detector.go:182-187
Change the password immediately in the associated system or service. Remove the hardcoded password from configuration files. Use environment variables or secrets management systems instead. Audit logs for unauthorized access.
SECRET-ENTmediumCWE-798High-Entropy Secret (potential unknown format)Detects high-entropy tokens in assignment expressions (key=value or key:value) when the key name suggests it might hold a secret (contains words like 'secret', 'token', 'password', 'key', 'auth', 'credential', 'bearer', etc.) and the value has Shannon entropy >= 4.5. Skips known benign patterns (hex digests, UUIDs, integrity hashes) and generated files.
/opt/shield/packages/secret-detector/detector.go:374-390
Verify if the detected value is actually a secret. If it is, rotate it immediately using the provider's management interface. If it is a legitimate non-secret high-entropy value (hash, checksum, etc.), add it to .shieldignore or rename the assignment key to avoid pattern matching.
DAST — Dynamic 37 rules
DAST-001criticalCWE-319TLS/SSL appears disabled or using weak protocolConfiguration files or source code patterns indicating TLS/SSL is disabled or using deprecated weak protocols (SSLv2, SSLv3, TLSv1.0). Detects patterns like ssl_protocols SSLv2, ssl=false, or tls=false in web configs and source files.
Web configuration files (nginx.conf, apache.conf, httpd.conf, .htaccess, *.conf), environment files (.env, .env.production, .env.staging), and application source code (*.go, *.py, *.js, *.ts, *.rb, *.java, *.php, *.jsx, *.tsx)
Enable TLS 1.2 or higher in all web server configurations. Remove SSLv2/v3 and TLSv1.0 from ssl_protocols directive. Set all ssl/tls flags to true or enabled. Update web server configuration files to enforce modern TLS versions only.
DAST-LIVE-001criticalCWE-319Application served over HTTP without TLSLive HTTP probe detects the application is served over HTTP (unencrypted) instead of HTTPS. This represents a critical confidentiality and integrity risk as all traffic can be intercepted.
Live endpoint/URL probing during runtime against HTTP targets
Enforce HTTPS for all application endpoints. Obtain and install a valid TLS certificate. Configure the web server to redirect HTTP to HTTPS. Set Strict-Transport-Security (HSTS) header to enforce HTTPS for future requests.
DAST-LIVE-012criticalCWE-295TLS connection failedLive probe fails to establish a TLS connection to the target HTTPS endpoint. This indicates a certificate issue, misconfigured TLS, or unreachable target.
TLS handshake during live HTTPS endpoint probes
Verify the TLS certificate is valid, not expired, and properly installed. Check certificate CN/SAN matches the domain. Ensure port 443 is open and accessible. Verify certificate chain is complete. Test with openssl s_client for detailed diagnostics.
DAST-LIVE-014criticalCWE-295TLS certificate expiredLive probe detects that the TLS certificate has already expired. This breaks HTTPS and will trigger browser warnings, disrupting service.
TLS certificate NotAfter timestamp during live HTTPS endpoint probes
Immediately renew the TLS certificate. Use Let's Encrypt for free automated certificates. If using paid certificates, renew before expiration. Implement automated renewal processes to prevent future expirations. Add monitoring alerts 30 days before expiry.
DAST-LIVE-016criticalCWE-200Environment file (.env) publicly accessibleLive probe detects that the .env file (commonly containing database passwords, API keys, secrets) is publicly accessible via HTTP GET on /.env endpoint, returning 200 OK.
HTTP GET /.env response during live sensitive path probes
Remove .env files from web root entirely. Store secrets in environment variables, secret management systems (HashiCorp Vault, AWS Secrets Manager), or config files outside the web directory. Configure web server to deny access to dotfiles: deny all for /. files in nginx or <FilesMatch> in Apache.
DAST-LIVE-017criticalCWE-200Git repository metadata publicly accessibleLive probe detects that the .git/config file (Git repository metadata) is publicly accessible via HTTP GET on /.git/config endpoint, returning 200 OK. Allows attackers to clone source code.
HTTP GET /.git/config response during live sensitive path probes
Remove .git directories from production deployments. Use .gitignore to exclude from builds. Configure web server to deny access: deny all for /.git/ in nginx or <FilesMatch ~ /\.git/> in Apache. Use containerization to ensure .git doesn't ship in production images.
DAST-003highCWE-319Non-HTTPS endpoint configuredHTTP endpoints (not HTTPS) configured for production use. Detects patterns like url: http://, endpoint: http://, base_url: http://, api_url: http://, or redirect: http:// pointing to non-localhost addresses. Excludes localhost and 127.0.0.1 which are development-only.
Configuration files (nginx.conf, apache.conf, *.conf, .env files) and application source code containing URL/endpoint definitions
Replace HTTP with HTTPS for all production endpoints. Ensure all URLs, API endpoints, and redirects use https:// protocol. Keep HTTP only for localhost development or use localhost/127.0.0.1 addresses.
DAST-008highCWE-352CSRF protection explicitly disabledCross-Site Request Forgery (CSRF) protection is explicitly disabled or set to false in source code or configuration. Detects patterns like csrf: false, xsrf: false, csrf_disabled, csrf_off, csrf_none, etc.
Application source code files (*.go, *.py, *.js, *.ts, *.rb, *.java, *.php, *.jsx, *.tsx) containing CSRF/XSRF configuration settings
Enable CSRF protection by default. Ensure CSRF tokens are generated for all state-changing requests (POST, PUT, DELETE). Implement proper token validation on the server side. Use framework-provided CSRF middleware. Never disable CSRF protection in production.
DAST-011highCWE-215Debug mode enabled — may expose sensitive informationDebug mode is enabled in production or staging configuration files. Detects patterns like DEBUG: true, DEBUG: 1, DEBUG: yes, DEBUG: on, debug_mode: true, or FLASK_DEBUG: true/1/yes/on.
Application source code files (*.go, *.py, *.js, *.ts, *.rb, *.java, *.php, *.jsx, *.tsx) and environment files (.env, .env.production, .env.staging) containing debug configuration
Disable debug mode in production and staging environments. Set DEBUG=false in environment variables. Remove verbose error messages from production responses. Use separate DEBUG settings for development-only environments. Ensure stack traces and sensitive data are not exposed in error pages.
DAST-LIVE-002highCWE-319Missing Strict-Transport-Security (HSTS) headerLive probe detects that the Strict-Transport-Security (HSTS) header is missing from HTTPS responses. Without HSTS, clients may still attempt HTTP connections on subsequent visits, enabling SSL stripping attacks.
HTTP response headers from live endpoint probes
Add the Strict-Transport-Security header to HTTPS responses: Strict-Transport-Security: max-age=31536000; includeSubDomains; preload. Set max-age to at least 1 year (31536000 seconds). Include subdomains to protect all application endpoints. Consider HSTS preload list submission.
DAST-LIVE-013highCWE-326Weak TLS versionLive probe detects that the TLS version negotiated is less than TLS 1.2 (e.g., TLS 1.0, TLS 1.1). These versions have known cryptographic weaknesses and are considered deprecated.
TLS handshake/ConnectionState during live HTTPS endpoint probes
Configure the server to require TLS 1.2 or higher. Disable TLS 1.0 and 1.1. In nginx: ssl_protocols TLSv1.2 TLSv1.3;. In Apache: SSLProtocol -all +TLSv1.2 +TLSv1.3. Update client libraries to support modern TLS.
DAST-LIVE-018highCWE-200Debug endpoint publicly accessibleLive probe detects that a /debug endpoint is publicly accessible, returning 200 OK. This endpoint typically exposes internal application state, configuration, or heap dumps.
HTTP GET /debug response during live sensitive path probes
Remove or disable debug endpoints in production. Restrict debug endpoints to localhost or internal networks only. Require authentication for any diagnostic endpoints. Use framework-level configuration to disable debug mode: DEBUG=False in Django, Flask, etc.
DAST-LIVE-020highCWE-200phpinfo() page publicly accessibleLive probe detects that /phpinfo.php endpoint is publicly accessible, returning 200 OK. Exposes detailed PHP configuration, loaded extensions, environment variables, and server info.
HTTP GET /phpinfo.php response during live sensitive path probes
Remove phpinfo.php from production servers entirely. Never leave test/debug files in production. Disable PHP error reporting on screen. Set display_errors = Off in php.ini. Remove file if found during deployment/audit.
DAST-LIVE-022highCWE-200Spring Boot Actuator endpoints exposedLive probe detects that Spring Boot Actuator endpoints (/actuator) are publicly accessible, returning 200 OK. Exposes application metrics, environment variables, beans, and configuration.
HTTP GET /actuator response during live sensitive path probes
Disable or restrict Spring Boot Actuator endpoints: set management.endpoints.web.exposure.exclude=* or expose only safe endpoints. Move actuator to internal/admin port. Require authentication: spring.security.user.name and spring.security.user.password. Use management.endpoints.web.base-path=/internal/actuator to hide from public.
DAST-LIVE-024highCWE-319HTTP does not redirect to HTTPSLive probe detects that HTTP requests to the application return 2xx (success) without redirecting to HTTPS. Allows unencrypted communication and enables man-in-the-middle attacks.
HTTP endpoint HTTP response status (200-299) during live HTTP-to-HTTPS redirect probes
Configure HTTP to HTTPS redirect on port 80: server { listen 80; return 301 https://$host$request_uri; } in nginx or <VirtualHost *:80> with Redirect permanent / https://... in Apache. Ensure all traffic is redirected before serving content.
DAST-LIVE-025highCWE-319HTTP redirects but not to HTTPSLive probe detects that HTTP requests redirect (3xx response) but not to an HTTPS URL. Redirect may go to another HTTP URL or a different domain, still exposing traffic.
HTTP endpoint with 3xx response and Location header not starting with https:// during live HTTP-to-HTTPS redirect probes
Ensure HTTP redirects to the HTTPS version of the same URL: return 301 https://$host$request_uri; in nginx. Verify Location header in 3xx responses starts with https://. Test HTTP-to-HTTPS redirect chain: http -> https, not http -> http.
DAST-002mediumCWE-942CORS allows all origins (*)Cross-Origin Resource Sharing (CORS) policy configured to allow all origins using the wildcard (*) pattern. Detects patterns like Access-Control-Allow-Origin: *, AllowOrigins: *, or allow_origin: * in configuration files.
Web configuration files (nginx.conf, apache.conf, httpd.conf, .htaccess, *.conf), environment files, and application source code detecting wildcard CORS patterns
Replace the wildcard (*) with specific trusted origins. Explicitly list only the domains that need CORS access. Use a dynamic CORS policy that validates request origins against a whitelist. Never use wildcards for CORS in production.
DAST-004mediumCWE-1021X-Frame-Options set to permissive valueX-Frame-Options header configured with permissive values (e.g., Allow) that permit the page to be framed by external sites, enabling clickjacking attacks. Detects patterns where X-Frame-Options contains 'ALLOW' keyword.
Web server configuration files (nginx.conf, apache.conf, httpd.conf, *.conf, .htaccess) containing X-Frame-Options directives
Set X-Frame-Options to either DENY (prevents all framing) or SAMEORIGIN (allows framing only by the same origin). Avoid permissive values like ALLOW or ALLOWALL. Use Content-Security-Policy frame-ancestors directive as a complementary control.
DAST-006mediumCWE-548Directory listing enabledDirectory listing/auto-indexing is enabled on the web server, allowing attackers to browse directory contents. Detects patterns like autoindex on, Options Indexes, or directory_listing: true.
Web server configuration files (nginx.conf, apache.conf, httpd.conf, *.conf, .htaccess) containing indexing directives
Disable directory listing: set autoindex off in nginx, remove Indexes from Options in Apache (use Options -Indexes), or set directory_listing: false. Ensure only intentionally exposed files are accessible via web.
DAST-007mediumCWE-601Potential open redirect — user-controlled redirect targetCode pattern for open redirect vulnerability where redirect/location targets are populated from user-controlled input parameters (req.*, request.*, params.*, query.*). Detects patterns like redirect(request.query), location(params.url), etc.
Application source code files (*.go, *.py, *.js, *.ts, *.rb, *.java, *.php, *.jsx, *.tsx) containing redirect or location statements
Validate redirect targets against a whitelist of allowed destinations before redirecting. Use absolute URL validation and ensure redirects stay within the same domain. Never trust user input for redirect URLs without strict validation. Use framework helpers like Rails redirect_to with only: parameter.
DAST-009mediumCWE-614Cookie set without Secure or HttpOnly flagsCookies are set without the Secure flag (preventing transmission over HTTPS only) or HttpOnly flag (preventing access from JavaScript). Detects patterns like secure: false or httponly: false in Set-Cookie or cookie directives.
Application source code files (*.go, *.py, *.js, *.ts, *.rb, *.java, *.php, *.jsx, *.tsx) containing cookie configuration
Set both Secure and HttpOnly flags on all cookies. Use Set-Cookie: name=value; Secure; HttpOnly; SameSite=Strict. The Secure flag prevents transmission over HTTP; HttpOnly prevents JavaScript access, mitigating XSS-based theft.
DAST-010mediumCWE-770Rate limiting disabled or not configuredRate limiting is explicitly disabled or not configured, leaving the application vulnerable to brute force and denial-of-service attacks. Detects patterns like rate_limit: false, rate_limit: disabled, rate_limit: off, rate_limit: 0, or rate_limit: none.
Application source code files (*.go, *.py, *.js, *.ts, *.rb, *.java, *.php, *.jsx, *.tsx) and configuration files containing rate limiting settings
Enable rate limiting on sensitive endpoints (login, API, password reset). Implement per-IP or per-user rate limits. Configure reasonable thresholds based on legitimate usage patterns. Use reverse proxy (nginx, Cloudflare) or framework-level middleware for rate limiting.
DAST-LIVE-003mediumCWE-693Missing X-Content-Type-Options headerLive probe detects that the X-Content-Type-Options header is missing from responses. Without this header, browsers may perform MIME sniffing, potentially leading to XSS or other content-type attacks.
HTTP response headers from live endpoint probes
Add X-Content-Type-Options: nosniff to all responses. This prevents browsers from guessing the content type and forces them to respect the declared Content-Type header.
DAST-LIVE-004mediumCWE-1021Missing X-Frame-Options header — clickjacking riskLive probe detects that the X-Frame-Options header is missing from responses. Without this header, the application can be embedded in a frame on another site, enabling clickjacking attacks.
HTTP response headers from live endpoint probes
Add X-Frame-Options header with a restrictive value: X-Frame-Options: DENY (prevent framing) or X-Frame-Options: SAMEORIGIN (allow framing only by same origin). Alternatively, use Content-Security-Policy: frame-ancestors 'none' or frame-ancestors 'self'.
DAST-LIVE-005mediumCWE-693Missing Content-Security-Policy headerLive probe detects that the Content-Security-Policy (CSP) header is missing from responses. Without CSP, the application is vulnerable to XSS attacks as browsers will execute any inline scripts and load resources from any origin.
HTTP response headers from live endpoint probes
Implement Content-Security-Policy header with a restrictive policy. Start with default-src 'self' and explicitly whitelist trusted sources for scripts, styles, images, etc. Avoid unsafe-inline and unsafe-eval. Use nonce or hash-based inline script policies for necessary inline content.
DAST-LIVE-009mediumCWE-942CORS allows all origins (*) — credentials could leakLive probe detects that Access-Control-Allow-Origin is set to * (wildcard), meaning the API accepts requests from any origin. If credentials (cookies, auth headers) are included, they may leak to malicious sites.
HTTP response header Access-Control-Allow-Origin from live endpoint probes
Replace wildcard (*) with specific trusted origins. Use a whitelist approach: Access-Control-Allow-Origin: https://trusted-domain.com. If credentials are needed, list specific origins and set Access-Control-Allow-Credentials: true. Never combine ACAO=* with credentials.
DAST-LIVE-015mediumCWE-295TLS certificate expires in <N> daysLive probe detects that the TLS certificate will expire soon (within 30 days). Proactive renewal is needed to prevent service disruption.
TLS certificate NotAfter timestamp during live HTTPS endpoint probes (expires within 30 days)
Renew the TLS certificate before expiration. Set up automated certificate renewal (Let's Encrypt with certbot, Kubernetes cert-manager). Configure monitoring to alert 30+ days before expiry. Test certificate installation in staging before production deployment.
DAST-LIVE-019mediumCWE-200Server status page publicly accessibleLive probe detects that the /server-status endpoint (typically Apache mod_status) is publicly accessible, returning 200 OK. Exposes server load, version, and request statistics.
HTTP GET /server-status response during live sensitive path probes
Restrict access to /server-status endpoint: use Allow from 127.0.0.1 in Apache mod_status or move behind authentication. Remove if not needed. Use internal monitoring/observability tools (Prometheus, Grafana) instead of public endpoints.
DAST-LIVE-021mediumCWE-200WordPress admin panel exposedLive probe detects that the WordPress admin login panel (/wp-admin/) is publicly accessible, returning 200 OK. Enables brute force attacks on admin credentials.
HTTP GET /wp-admin/ response during live sensitive path probes
Restrict access to /wp-admin/ to known IPs or via VPN. Use security plugins (Wordfence, iThemes Security) to require 2FA for admin login. Rename admin account (not 'admin'). Change default ports. Disable XML-RPC if not needed.
DAST-005lowCWE-200Server version information exposedWeb server configuration leaks version information through headers. Detects patterns like server_tokens on, ServerSignature On, or expose_php = On in web server configurations.
Web server configuration files (nginx.conf, apache.conf, httpd.conf, *.conf, .htaccess) containing server token or signature directives
Disable server token exposure: set server_tokens off in nginx, ServerSignature Off in Apache, or expose_php = Off in PHP configurations. Remove or minimize the Server header to avoid disclosing version information that could aid reconnaissance.
DAST-LIVE-006lowCWE-79Missing X-XSS-Protection headerLive probe detects that the X-XSS-Protection header is missing from responses. This legacy header provided browser-level XSS protection in older browsers (less relevant with modern CSP but still a defense-in-depth measure).
HTTP response headers from live endpoint probes
Add X-XSS-Protection header to responses: X-XSS-Protection: 1; mode=block. This enables the browser's XSS filter and blocks page rendering if XSS is detected. Note: This is a legacy header; rely on Content-Security-Policy as primary XSS defense.
DAST-LIVE-007lowCWE-200Missing Referrer-Policy headerLive probe detects that the Referrer-Policy header is missing from responses. Without this header, browsers will leak referrer information across origins, potentially disclosing sensitive URLs.
HTTP response headers from live endpoint probes
Add Referrer-Policy header to restrict referrer leakage: Referrer-Policy: no-referrer (never send referrer) or Referrer-Policy: strict-origin-when-cross-origin (send origin only for cross-origin requests). Choose based on application requirements.
DAST-LIVE-008lowCWE-693Missing Permissions-Policy headerLive probe detects that the Permissions-Policy header (formerly Feature-Policy) is missing from responses. This header controls access to browser features (camera, microphone, geolocation, payment APIs, etc.).
HTTP response headers from live endpoint probes
Add Permissions-Policy header to restrict feature access: Permissions-Policy: geolocation=(), microphone=(), camera=(). Explicitly disable features not needed by the application. Use () to disable globally or 'self' to allow same-origin only.
DAST-LIVE-010lowCWE-200Server header discloses version informationLive probe detects that the Server header in HTTP responses contains version information (e.g., nginx/1.23.1, Apache/2.4.48). This aids attackers in reconnaissance and vulnerability scanning.
HTTP response header Server from live endpoint probes
Remove or minimize the Server header. Configure web servers to not expose version: set server_tokens off in nginx, remove ServerTokens Prod in Apache, or use custom non-informative Server header values.
DAST-LIVE-011lowCWE-200X-Powered-By header exposes technology stackLive probe detects that the X-Powered-By header reveals the application technology stack (e.g., Express, ASP.NET, PHP 7.4). This information aids attackers in targeted vulnerability research.
HTTP response header X-Powered-By from live endpoint probes
Remove the X-Powered-By header from all responses. Disable it in framework configuration (e.g., app.disable('x-powered-by') in Express). If needed for debugging, configure it only in development environments.
DAST-LIVE-023lowCWE-200GraphQL endpoint exposed (check introspection)Live probe detects that a GraphQL endpoint (/graphql) is publicly accessible, returning 200 OK. May allow schema introspection, revealing API structure and potential attack vectors.
HTTP GET /graphql response during live sensitive path probes
Disable GraphQL introspection in production: set introspection: false in apollo-server or schema.introspection = false in graphql-core. Require authentication for GraphQL endpoint. Rate-limit queries. Use query complexity analysis to prevent DoS. Validate all inputs strictly.
DAST-LIVE-026infoCWE-200robots.txt found — check for sensitive path disclosureLive probe detects that robots.txt file exists at the root (HTTP 200 on /robots.txt). While informational, it may inadvertently disclose sensitive paths if not carefully maintained.
HTTP GET /robots.txt response during live sensitive path probes
Review robots.txt contents to ensure it does not disclose sensitive paths or internal URLs. Use robots.txt only to guide public search engines. For truly sensitive paths, use authentication instead of relying on robots.txt. Keep robots.txt minimal and maintained.
Containers 11 rules
CONTAINER-005criticalCWE-829curl | bash — untrusted remote code execution in buildDetects the dangerous pattern of piping curl output directly to bash, which executes untrusted remote code during container build with no verification or inspection.
Dockerfile:line (RUN instruction)
Download scripts separately, verify checksums or signatures, and review contents before execution. Use package managers when possible, or break into discrete steps: RUN curl ... -o script.sh && chmod +x script.sh && ./script.sh
CONTAINER-008criticalCWE-250Privileged/capability escalation in containerDetects RUN instructions that use --privileged flag or --cap-add options, which grant excessive Linux capabilities and can lead to container escape or host compromise.
Dockerfile:line (RUN instruction)
Avoid --privileged mode. Use specific minimal capabilities with --cap-drop all and --cap-add ONLY_NEEDED_CAPS if absolutely required. Review if privileged access is truly necessary or if application logic can be refactored.
CONTAINER-009criticalCWE-250Docker Compose: privileged mode enabledDetects 'privileged: true' in docker-compose.yml files, which grants excessive capabilities to containers and significantly increases attack surface.
docker-compose.yml:line (service definition)
Remove the 'privileged: true' setting. If specific capabilities are needed, use 'cap_add' with only the minimal required capabilities instead (e.g., cap_add: [NET_ADMIN]).
CONTAINER-001highCWE-250Container runs as root userDetects when a Dockerfile explicitly sets the user to root using the USER ROOT instruction, which violates the principle of least privilege and increases attack surface.
Dockerfile:line (identified by line number during scan)
Replace 'USER root' with a non-root user. Create a dedicated application user in the Dockerfile before the USER instruction (e.g., 'RUN useradd -m appuser && USER appuser').
CONTAINER-007highCWE-798Potential secret in ENV instructionDetects ENV instructions that set sensitive variables (PASSWORD, SECRET, API_KEY, TOKEN, PRIVATE_KEY) with hardcoded values, which are baked into the image and visible in docker inspect.
Dockerfile:line (ENV instruction)
Never hardcode secrets in Dockerfiles. Use build-time secrets via docker build --secret, environment variables injected at runtime, or container orchestration secret management systems (Kubernetes Secrets, Docker Secrets).
CONTAINER-010highCWE-668Docker Compose: host network modeDetects 'network_mode: host' in docker-compose.yml, which disables container network isolation and exposes all host network interfaces to the container.
docker-compose.yml:line (service definition)
Remove 'network_mode: host'. Use the default bridge network or create a custom user-defined network. Only use host network if absolutely required and document the security justification.
CONTAINER-011highCWE-668Docker Compose: host PID namespace sharingDetects 'pid: host' in docker-compose.yml, which allows container to see and interact with all host processes, breaking process isolation.
docker-compose.yml:line (service definition)
Remove 'pid: host'. Use the default isolated PID namespace. If inter-service communication is needed, use named volumes or network communication instead.
CONTAINER-002mediumCWE-1104Base image uses :latest tag (non-deterministic builds)Detects use of the ':latest' tag in FROM instructions, which makes builds non-deterministic and allows automatic pulling of new base image versions without explicit control.
Dockerfile:line (FROM instruction)
Replace ':latest' with a specific version tag or digest. For example, use 'ubuntu:22.04' instead of 'ubuntu:latest' or specify a full digest hash for reproducible builds.
CONTAINER-004mediumCWE-200Exposing potentially sensitive portDetects EXPOSE instructions that publish sensitive ports (SSH:22, MySQL:3306, PostgreSQL:5432, Redis:6379, MongoDB:27017, Elasticsearch:9200), which may enable unauthorized access.
Dockerfile:line (EXPOSE instruction)
Avoid exposing sensitive database and system ports publicly. Use EXPOSE only for application-facing ports needed by end users. Restrict network access via firewall rules and network policies.
CONTAINER-003lowCWE-829Use COPY instead of ADD for local filesDetects use of ADD instruction for local files instead of COPY, which can unintentionally unpack tarballs or perform unexpected file transformations.
Dockerfile:line (ADD instruction)
Replace ADD with COPY for copying local files. Use ADD only when you specifically need its special behaviors (automatic tarball unpacking or remote URL fetching).
CONTAINER-006lowCWE-693HEALTHCHECK explicitly disabledDetects explicit disabling of container healthchecks via 'HEALTHCHECK NONE', which removes the ability to automatically detect and recover from container failures.
Dockerfile:line (HEALTHCHECK instruction)
Remove the HEALTHCHECK NONE instruction or replace it with a valid healthcheck. Define a proper HEALTHCHECK command that monitors application readiness (e.g., HEALTHCHECK CMD curl --fail http://localhost:8080/health || exit 1).
Infrastructure as Code 16 rules
IAC-CFN-001criticalCWE-284CloudFormation: S3 bucket with public accessDetects CloudFormation templates configuring S3 buckets with public read or public read-write access (PublicRead or PublicReadWrite ACL).
CloudFormation template files (YAML/JSON containing 'cloudformation', 'cfn-', or 'template' in name), detected when line contains `PublicRead` or `PublicReadWrite`
Set the bucket's `PublicAccessBlockConfiguration` to block all public access, and use CloudFront + OAI for public content distribution. Public S3 buckets are one of the most common breach vectors.
IAC-K8S-001criticalCWE-250Kubernetes: privileged containerDetects Kubernetes containers configured with `privileged: true`, granting all capabilities and full host kernel access to the container.
Kubernetes YAML files (.yaml or .yml) in k8s/, kubernetes/, manifests/, deploy/, helm/, or charts/ directories, detected when line contains `privileged: true`
Remove `privileged: true` from the container's securityContext. If a specific capability is required, add it explicitly via `capabilities.add: [NET_ADMIN]` rather than enabling all privileges.
IAC-K8S-005criticalCWE-250Kubernetes: ALL capabilities grantedDetects Kubernetes containers with ALL Linux capabilities enabled via securityContext, granting excessive kernel privileges.
Kubernetes YAML files (.yaml or .yml) in k8s/, kubernetes/, manifests/, deploy/, helm/, or charts/ directories, line contains `ALL` and case-insensitive match for `capabilit`
Drop `ALL` capabilities then add back only what's needed: `capabilities: { drop: [ALL], add: [NET_BIND_SERVICE] }`. Most workloads need zero capabilities.
IAC-TF-003criticalCWE-798Potential hardcoded secret in Terraform configDetects hardcoded credentials in Terraform files, including passwords, secret keys, and access keys assigned as string values.
Terraform files (.tf or .tf.json), detected via regex pattern `(password|secret_key|access_key)\s*=\s*"[^"]{8,}"` (case-insensitive)
Move the secret out of Terraform code into a secret manager (AWS Secrets Manager, SSM Parameter Store with SecureString, or Hashicorp Vault) and reference it via a data source. Rotate the secret since it's now in state files and git history.
IAC-TF-004criticalCWE-284S3 bucket with public ACLDetects S3 bucket configurations with public read or public read-write ACLs, making bucket contents accessible to anyone on the internet.
Terraform files (.tf or .tf.json), line contains `acl` keyword and either `"public-read"` or `"public-read-write"`
Remove the public ACL. Set `acl = "private"` and serve content via CloudFront with origin access identity, or via signed URLs. Block public access at the bucket level with `aws_s3_bucket_public_access_block`.
IAC-CFN-002highCWE-284CloudFormation: wildcard principal in IAM policyDetects CloudFormation IAM policies with wildcard principals (`"*"`), making the resource accessible to any AWS account.
CloudFormation template files (YAML/JSON containing 'cloudformation', 'cfn-', or 'template' in name), line contains `"*"` and case-insensitive `principal` keyword
Replace the wildcard Principal with specific AWS account IDs, IAM ARNs, or service principals. Wildcard principals make the resource accessible to any AWS account.
IAC-CFN-003highCWE-311CloudFormation: RDS storage encryption disabledDetects CloudFormation RDS database configurations with `StorageEncrypted` set to false, leaving database data unencrypted at rest.
CloudFormation template files (YAML/JSON containing 'cloudformation', 'cfn-', or 'template' in name), line contains both `StorageEncrypted` and `false`
Set `StorageEncrypted: true` on the RDS instance. AWS performs at-rest encryption transparently with KMS — there's no perf penalty and it's required for most compliance frameworks.
IAC-K8S-002highCWE-250Kubernetes: container runs as root (UID 0)Detects Kubernetes containers configured with `runAsUser: 0`, running with root privileges which increases blast radius if the container is compromised.
Kubernetes YAML files (.yaml or .yml) in k8s/, kubernetes/, manifests/, deploy/, helm/, or charts/ directories, detected when line contains `runAsUser: 0`
Set `runAsUser` to a non-zero UID (e.g. `runAsUser: 1000`, `runAsNonRoot: true`). Build the image with a non-root user baked in so it works without privileged init.
IAC-K8S-003highCWE-668Kubernetes: host network enabledDetects Kubernetes pods configured with `hostNetwork: true`, allowing the pod to access the host's network namespace and bypass NetworkPolicy isolation.
Kubernetes YAML files (.yaml or .yml) in k8s/, kubernetes/, manifests/, deploy/, helm/, or charts/ directories, detected when line contains `hostNetwork: true`
Remove `hostNetwork: true`. Host networking lets the pod see all host network interfaces and bypass NetworkPolicy. If specific host ports are needed, use `hostPort` on the container instead.
IAC-K8S-004highCWE-668Kubernetes: host PID namespace sharingDetects Kubernetes pods configured with `hostPID: true`, allowing the container to see and signal host processes, enabling container-escape attacks.
Kubernetes YAML files (.yaml or .yml) in k8s/, kubernetes/, manifests/, deploy/, helm/, or charts/ directories, detected when line contains `hostPID: true`
Remove `hostPID: true`. Sharing the host PID namespace lets the container enumerate and signal host processes — a common container-escape primitive.
IAC-TF-001highCWE-284Security group allows ingress from 0.0.0.0/0Detects Terraform security group rules that allow unrestricted ingress from any IP address (0.0.0.0/0), exposing infrastructure to public network access.
Terraform files (.tf or .tf.json), detected when line contains `cidr_blocks = ["0.0.0.0/0"]`
Replace `0.0.0.0/0` with the specific CIDR ranges that need access (e.g. office IPs, VPN range, peered VPC CIDR). For services that genuinely must be public, layer on additional controls like WAF or per-request auth.
IAC-TF-002highCWE-311Encryption explicitly disabledDetects Terraform configuration where encryption is explicitly set to false on storage resources (RDS, S3, EBS, etc.), leaving data unencrypted at rest.
Terraform files (.tf or .tf.json), detected via regex pattern matching `encrypt\w*\s*=\s*false` (case-insensitive)
Set encryption to true (e.g. `storage_encrypted = true` for RDS, `server_side_encryption_configuration` for S3). At-rest encryption is free on AWS and required by most compliance frameworks.
IAC-TF-006highCWE-250Wildcard IAM action — overly permissive policyDetects IAM policies in Terraform with wildcard actions (`"*"`), granting all permissions on a resource and violating least-privilege principle.
Terraform files (.tf or .tf.json), line contains `"*"` and either `actions` or `Action` keyword
Replace `"*"` actions with the specific actions actually needed (e.g. `["s3:GetObject", "s3:PutObject"]`). Wildcard policies violate least-privilege and dramatically expand blast radius if credentials leak.
IAC-K8S-006mediumCWE-770Kubernetes: no resource limits definedDetects Kubernetes containers with empty resource specifications (`resources: {}`), allowing unbounded CPU/memory consumption that can starve other pods.
Kubernetes YAML files (.yaml or .yml) in k8s/, kubernetes/, manifests/, deploy/, helm/, or charts/ directories, detected when line contains `resources: {}`
Set explicit `resources.requests` and `resources.limits` for cpu and memory. Without limits, a runaway pod can starve neighbors on the same node and trigger OOM kills of unrelated workloads.
IAC-K8S-007mediumCWE-1104Kubernetes: image uses :latest tagDetects Kubernetes container images using the `:latest` tag, making deployments non-deterministic and preventing reliable rollback.
Kubernetes YAML files (.yaml or .yml) in k8s/, kubernetes/, manifests/, deploy/, helm/, or charts/ directories, detected via regex `image:\s*\S+:latest\b`
Pin the image to a tag or digest (`image: nginx:1.27.3` or `image: nginx@sha256:...`). `:latest` makes rollouts non-deterministic and breaks rollback.
IAC-TF-005mediumCWE-778Logging disabled on infrastructure resourceDetects Terraform resources where logging is explicitly disabled or set to false, reducing auditability and incident investigation capabilities.
Terraform files (.tf or .tf.json), line contains both `logging` and `false`
Enable resource-level logging (CloudTrail data events for S3, VPC Flow Logs, ALB access logs, RDS audit logs). Without logs, you can't investigate incidents or prove compliance.
Dependencies 1 rules
DEP-CVEdynamicCWE-1395Known vulnerability in dependency (CVE/OSV record)Detects published vulnerabilities in direct and transitive dependencies by querying the OSV (Open Source Vulnerabilities) database. The scanner parses dependency manifests (package.json, go.mod, requirements.txt, Pipfile.lock, Gemfile.lock, package-lock.json) and checks each package version against OSV's vulnerability records for npm, Go, PyPI, and RubyGems ecosystems.
Dependency manifest files (package.json, package-lock.json, go.mod, requirements.txt, Pipfile.lock, Gemfile.lock) at the package name and resolved/locked version. Reported location is the manifest file path with line 0.
Upgrade the vulnerable package to a version at or above the 'fixed' version reported by OSV in the vulnerability record. If no fixed version exists, evaluate whether to remove the dependency or accept the risk. The fix version is extracted from the OSV vulnerability's affected.ranges[].events[].fixed field.
CLI Reference
shield login # authenticate (opens /settings/cli-tokens)
shield scan . --submit --project ID --org ID # scan + upload results
shield version # print CLI version