-
Notifications
You must be signed in to change notification settings - Fork 9
Expand file tree
/
Copy pathdefault_rules.json
More file actions
1281 lines (1281 loc) · 53 KB
/
Copy pathdefault_rules.json
File metadata and controls
1281 lines (1281 loc) · 53 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
167
168
169
170
171
172
173
174
175
176
177
178
179
180
181
182
183
184
185
186
187
188
189
190
191
192
193
194
195
196
197
198
199
200
201
202
203
204
205
206
207
208
209
210
211
212
213
214
215
216
217
218
219
220
221
222
223
224
225
226
227
228
229
230
231
232
233
234
235
236
237
238
239
240
241
242
243
244
245
246
247
248
249
250
251
252
253
254
255
256
257
258
259
260
261
262
263
264
265
266
267
268
269
270
271
272
273
274
275
276
277
278
279
280
281
282
283
284
285
286
287
288
289
290
291
292
293
294
295
296
297
298
299
300
301
302
303
304
305
306
307
308
309
310
311
312
313
314
315
316
317
318
319
320
321
322
323
324
325
326
327
328
329
330
331
332
333
334
335
336
337
338
339
340
341
342
343
344
345
346
347
348
349
350
351
352
353
354
355
356
357
358
359
360
361
362
363
364
365
366
367
368
369
370
371
372
373
374
375
376
377
378
379
380
381
382
383
384
385
386
387
388
389
390
391
392
393
394
395
396
397
398
399
400
401
402
403
404
405
406
407
408
409
410
411
412
413
414
415
416
417
418
419
420
421
422
423
424
425
426
427
428
429
430
431
432
433
434
435
436
437
438
439
440
441
442
443
444
445
446
447
448
449
450
451
452
453
454
455
456
457
458
459
460
461
462
463
464
465
466
467
468
469
470
471
472
473
474
475
476
477
478
479
480
481
482
483
484
485
486
487
488
489
490
491
492
493
494
495
496
497
498
499
500
501
502
503
504
505
506
507
508
509
510
511
512
513
514
515
516
517
518
519
520
521
522
523
524
525
526
527
528
529
530
531
532
533
534
535
536
537
538
539
540
541
542
543
544
545
546
547
548
549
550
551
552
553
554
555
556
557
558
559
560
561
562
563
564
565
566
567
568
569
570
571
572
573
574
575
576
577
578
579
580
581
582
583
584
585
586
587
588
589
590
591
592
593
594
595
596
597
598
599
600
601
602
603
604
605
606
607
608
609
610
611
612
613
614
615
616
617
618
619
620
621
622
623
624
625
626
627
628
629
630
631
632
633
634
635
636
637
638
639
640
641
642
643
644
645
646
647
648
649
650
651
652
653
654
655
656
657
658
659
660
661
662
663
664
665
666
667
668
669
670
671
672
673
674
675
676
677
678
679
680
681
682
683
684
685
686
687
688
689
690
691
692
693
694
695
696
697
698
699
700
701
702
703
704
705
706
707
708
709
710
711
712
713
714
715
716
717
718
719
720
721
722
723
724
725
726
727
728
729
730
731
732
733
734
735
736
737
738
739
740
741
742
743
744
745
746
747
748
749
750
751
752
753
754
755
756
757
758
759
760
761
762
763
764
765
766
767
768
769
770
771
772
773
774
775
776
777
778
779
780
781
782
783
784
785
786
787
788
789
790
791
792
793
794
795
796
797
798
799
800
801
802
803
804
805
806
807
808
809
810
811
812
813
814
815
816
817
818
819
820
821
822
823
824
825
826
827
828
829
830
831
832
833
834
835
836
837
838
839
840
841
842
843
844
845
846
847
848
849
850
851
852
853
854
855
856
857
858
859
860
861
862
863
864
865
866
867
868
869
870
871
872
873
874
875
876
877
878
879
880
881
882
883
884
885
886
887
888
889
890
891
892
893
894
895
896
897
898
899
900
901
902
903
904
905
906
907
908
909
910
911
912
913
914
915
916
917
918
919
920
921
922
923
924
925
926
927
928
929
930
931
932
933
934
935
936
937
938
939
940
941
942
943
944
945
946
947
948
949
950
951
952
953
954
955
956
957
958
959
960
961
962
963
964
965
966
967
968
969
970
971
972
973
974
975
976
977
978
979
980
981
982
983
984
985
986
987
988
989
990
991
992
993
994
995
996
997
998
999
1000
[
{
"id": "dangerous_delete",
"risk": "high",
"action": "block",
"title": "递归强制删除根目录 / 家目录 / 上级目录",
"desc": "rm -rf 直接作用在 /、~ 或 .. 上,会把整块目录不可恢复地删掉。正常开发几乎不可能需要这样做。",
"title_en": "Recursive force-delete of / , ~ or the parent dir",
"desc_en": "rm -rf pointed at /, ~ or .. wipes an entire directory tree irreversibly. Almost never something normal development needs.",
"tools": [
"Bash"
],
"field": "command",
"pattern": "\\brm\\s+(-[a-zA-Z]*r[a-zA-Z]*f[a-zA-Z]*|-[a-zA-Z]*f[a-zA-Z]*r[a-zA-Z]*)\\s+(/|~|\\$HOME|\\.\\.)(\\s|$)"
},
{
"id": "disk_overwrite",
"risk": "high",
"action": "block",
"title": "磁盘级写入 / 分区操作",
"desc": "dd、mkfs、fdisk、parted 直接操作磁盘或分区,会清空数据,甚至让系统无法启动。",
"title_en": "Raw disk write / partitioning",
"desc_en": "dd, mkfs, fdisk, parted operate on raw disks or partitions — they erase data and can leave the system unbootable.",
"tools": [
"Bash"
],
"field": "command",
"pattern": "(?<![\\w-])(dd|mkfs|fdisk|parted)(?![\\w-])"
},
{
"id": "curl_pipe_shell",
"risk": "high",
"action": "block",
"title": "下载脚本直接管道执行",
"desc": "从网上下载的内容不落地、直接交给 shell 执行,你看不到到底跑了什么。一键安装脚本常这么写,也是植入恶意代码的经典手法。",
"title_en": "Download piped straight into a shell",
"desc_en": "Content fetched from the network is executed without ever being saved, so you never see what actually ran. Common in one-line installers — and a classic way to plant malicious code.",
"tools": [
"Bash"
],
"field": "command",
"pattern": "(curl|wget)[^|;\\n]*\\|\\s*(sudo\\s+)?(sh|bash|zsh)\\b"
},
{
"id": "reverse_shell_pattern",
"risk": "high",
"action": "block",
"title": "反弹 Shell",
"desc": "把本机的 shell 连到一个远程地址,让外部可以远程控制这台机器。正常开发几乎用不到。",
"title_en": "Reverse shell",
"desc_en": "Connects a local shell out to a remote address so an outside party can control this machine. Almost never legitimate in development.",
"tools": [
"Bash"
],
"field": "command",
"pattern": ">&\\s*/dev/tcp/\\S+/\\d+|\\b(nc|ncat|netcat)\\b[^\\n]*-[a-zA-Z]*e[a-zA-Z]*\\s+/bin/(ba)?sh\\b|\\b(nc|ncat|netcat)\\b[^\\n]*-[a-zA-Z]*c[a-zA-Z]*\\s+(/bin/)?(ba)?sh\\b|\\bsocat\\b[^\\n]*exec:['\"]?/?(bin/)?(ba)?sh\\b|/bin/(ba)?sh\\s+-i\\s*(<|>&)|\\bmkfifo\\b[^\\n]*\\b(nc|ncat|netcat)\\b[^\\n]*\\|\\s*(/bin/)?(ba)?sh\\b"
},
{
"id": "shell_escape_via_utility",
"risk": "high",
"action": "block",
"title": "借日常工具逃逸出 shell",
"desc": "用 find -exec、awk system()、vim -c、tar --checkpoint-action 这类看似无害的工具间接启动 shell,通常是为了绕过限制。",
"title_en": "Shell escape via an everyday utility",
"desc_en": "Uses find -exec, awk system(), vim -c, tar --checkpoint-action and similar to spawn a shell indirectly — usually to slip past restrictions.",
"tools": [
"Bash"
],
"field": "command",
"pattern": "\\bfind\\b[^\\n]*-exec\\s+(/bin/)?(ba|z)?sh\\b|\\bawk\\b[^\\n]*system\\s*\\(\\s*[\"']?(/bin/)?(ba|z)?sh\\b|\\bperl\\b[^\\n]*\\bexec\\s+[\"']?(/bin/)?(ba|z)?sh\\b|\\bpython3?\\b[^\\n]*(pty\\.spawn|os\\.system)\\s*\\(\\s*[\"']?(/bin/)?(ba|z)?sh\\b|\\btar\\b[^\\n]*--checkpoint-action=exec=[^\\n]*?\\b(/bin/)?(ba|z)?sh\\b|\\b(vim?|nvim)\\b[^\\n]*-c\\s+[\"']?:?(shell|!\\s*(/bin/)?(ba|z)?sh)\\b|\\bzip\\b[^\\n]*--unzip-command=[^\\n]*?\\b(/bin/)?(ba|z)?sh\\b|\\bscript\\s+(-[a-zA-Z]*c\\b|(-\\S+\\s+)*-c\\b)[^\\n]*?\\b(/bin/)?(ba|z)?sh\\b|\\bssh\\b[^\\n]*ProxyCommand=[^\\n]*?\\b(/bin/)?(ba|z)?sh\\b"
},
{
"id": "encoded_payload_exec",
"risk": "high",
"action": "block",
"title": "解码后执行隐藏内容",
"desc": "把 base64 / 十六进制编码的内容解码后直接执行。编码的目的通常就是让人看不出要跑的是什么。",
"title_en": "Decode-then-execute hidden payload",
"desc_en": "Decodes base64 / hex content and runs it directly. The encoding usually exists precisely so nobody can read what is about to run.",
"tools": [
"Bash"
],
"field": "command",
"pattern": "\\b(base64\\s+(-d|--decode)|xxd\\s+-r\\s+-p?)\\b[^|;\\n]*\\|\\s*(sudo\\s+)?(sh|bash|zsh|python3?)\\b"
},
{
"id": "curl_download_then_exec",
"risk": "high",
"action": "confirm",
"title": "下载脚本后再执行",
"desc": "先用 curl / wget 把脚本下载到本地,再单独运行它。放行前看清下载地址和脚本内容。",
"title_en": "Download a script, then run it",
"desc_en": "curl / wget saves a script locally, then it gets executed separately. Check the download URL and the script before allowing.",
"tools": [
"Bash"
],
"field": "command",
"pattern": "(?=.*\\b(curl|wget2?)\\b[^\\n]*(-o\\b|-O\\b|--output\\b|--remote-name\\b))(?=.*\\.(sh|py|pl|rb)\\b)(?=.*\\b(bash|sh|zsh|python3?|perl|ruby|chmod\\s+\\+x|\\./)\\b)"
},
{
"id": "ssh_tunnel_reverse_proxy",
"risk": "medium",
"action": "confirm",
"title": "SSH 隧道 / 端口转发",
"desc": "ssh -R / -L / -D、socat、chisel 会在本机和远程之间打通端口,可能把内网服务暴露到外面。",
"title_en": "SSH tunnel / port forwarding",
"desc_en": "ssh -R / -L / -D, socat or chisel open a port path between this machine and a remote host, potentially exposing internal services.",
"tools": [
"Bash"
],
"field": "command",
"pattern": "\\bssh\\b[^\\n]*\\s-[a-zA-Z]*[RDL][a-zA-Z]*\\b|\\bsocat\\b|\\bchisel\\b\\s+(client|server)\\b"
},
{
"id": "covert_tunnel_tool_execution",
"risk": "medium",
"action": "confirm",
"title": "DNS / ICMP 隐蔽隧道工具",
"desc": "dnscat2、iodine、ptunnel 等把数据藏进 DNS 或 ping 流量里往外传的工具,用来绕过防火墙。",
"title_en": "DNS / ICMP covert-tunnel tool",
"desc_en": "dnscat2, iodine, ptunnel and friends smuggle data inside DNS or ping traffic to get past firewalls.",
"tools": [
"Bash"
],
"field": "command",
"pattern": "\\bdnscat2?\\b|\\biodine\\b|\\bdns2tcp\\b|\\bptunnel\\b|\\bicmptunnel\\b|\\bhans\\s+-[cs]\\b|\\bpingtunnel\\b"
},
{
"id": "crypto_miner_pool_domain_command",
"risk": "medium",
"action": "confirm",
"title": "连接挖矿矿池",
"desc": "命令里出现矿池地址或 stratum 协议,是挖矿木马的典型特征。",
"title_en": "Connecting to a crypto-mining pool",
"desc_en": "The command references a mining-pool domain or the stratum protocol — a hallmark of crypto-mining malware.",
"tools": [
"Bash"
],
"field": "command",
"pattern": "\\bstratum\\+(tcp|ssl|tcps)://|\\b(pool\\.minergate\\.com|pool\\.minexmr\\.com|opmoner\\.com|crypto-pool\\.fr|backup-pool\\.com|monerohash\\.com|poolto\\.be|xminingpool\\.com|prohash\\.net|dwarfpool\\.com|crypto-pools\\.org|monero\\.net|hashinvest\\.net|moneropool\\.com|xmrpool\\.eu|ppxxmr\\.com|alimabi\\.cn|aeon-pool\\.com)\\b"
},
{
"id": "c2_framework_execution",
"risk": "high",
"action": "confirm",
"title": "渗透测试 / C2 框架",
"desc": "msfconsole、cobaltstrike、sliver、havoc 这类攻击框架。除非你正在做授权的安全测试,否则不该出现。",
"title_en": "Pentest / C2 framework",
"desc_en": "msfconsole, cobaltstrike, sliver, havoc and similar attack frameworks. Should not appear unless you are running an authorized security test.",
"tools": [
"Bash"
],
"field": "command",
"pattern": "\\bmsfconsole\\b|\\bmsfvenom\\b|\\bmsfdb\\b|\\bcobaltstrike\\b|\\bteamserver\\b|\\bpowershell.?empire\\b|\\bsliver-(client|server)\\b|\\bhavoc\\b|\\bmimikatz\\b|\\bimpacket-[a-zA-Z]+\\b|\\bcrackmapexec\\b|\\bresponder\\.py\\b|\\bpacu\\b"
},
{
"id": "post_exploitation_tool_execution",
"risk": "high",
"action": "confirm",
"title": "后渗透 / 内网横向工具",
"desc": "linpeas、bloodhound、netexec、smbmap 等用来提权和探测内网的工具。",
"title_en": "Post-exploitation / lateral-movement tool",
"desc_en": "linpeas, bloodhound, netexec, smbmap and similar tools for privilege escalation and internal network reconnaissance.",
"tools": [
"Bash"
],
"field": "command",
"pattern": "\\blinpeas(\\.sh)?\\b|\\bnetexec\\b|\\bbloodhound\\b|\\bsharphound\\b|\\bsmbmap\\b|\\brpcclient\\b|\\benum4linux(-ng)?\\b"
},
{
"id": "mcp_suspicious_tool_name",
"risk": "high",
"action": "confirm",
"title": "可疑的 MCP 工具",
"desc": "要调用的 MCP 工具名字里带 reverse-shell / c2 / beacon / backdoor 字样。",
"title_en": "Suspicious MCP tool",
"desc_en": "The MCP tool being called has reverse-shell / c2 / beacon / backdoor in its name.",
"tools": [
"*"
],
"field": "tool_name",
"pattern": "^mcp__[a-zA-Z0-9_-]*(reverse[_-]?shell|c2server|[_-]c2[_-]|beacon|backdoor)"
},
{
"id": "pentest_recon_tool_execution",
"risk": "medium",
"action": "log",
"title": "扫描 / 爆破工具",
"desc": "nmap、masscan、sqlmap、hydra、nikto 等端口扫描或暴力破解工具。",
"title_en": "Scanning / brute-force tool",
"desc_en": "nmap, masscan, sqlmap, hydra, nikto and similar port-scanning or brute-forcing tools.",
"tools": [
"Bash"
],
"field": "command",
"pattern": "\\bnmap\\b|\\bmasscan\\b|\\bsqlmap\\b|\\bhydra\\b|\\bnikto\\b|\\b(gobuster|dirbuster|dirb)\\b|\\bwpscan\\b|\\bhashcat\\b|\\bjohn\\s+(--wordlist|--format|--rules)\\b|\\brustscan\\b|\\barp-scan\\b|\\bnbtscan\\b|\\bamass\\b|\\bsubfinder\\b|\\bkatana\\b|\\bgau\\b|\\bparamspider\\b|\\bwaybackurls\\b|\\bfierce\\b|\\bdnsenum\\b|\\bffuf\\b|\\bferoxbuster\\b|\\bdirsearch\\b|\\bjaeles\\b|\\bdalfox\\b|\\bx8\\b|\\barjun\\b|\\bwafw00f\\b"
},
{
"id": "chmod_world_writable_recursive",
"risk": "high",
"action": "block",
"title": "把整棵目录树设成所有人可写",
"desc": "chmod 777 递归作用到 / 或家目录,之后任何用户、任何程序都能改这些文件。",
"title_en": "Make a whole directory tree world-writable",
"desc_en": "chmod 777 applied recursively to / or the home dir — afterwards any user or program can modify those files.",
"tools": [
"Bash"
],
"field": "command",
"pattern": "\\bchmod\\s+(-R\\s+)?777\\b.*\\s(/|~)"
},
{
"id": "chown_root_recursive",
"risk": "high",
"action": "block",
"title": "递归更改根目录 / 家目录的所有者",
"desc": "会把系统或家目录下所有文件的归属一起改掉,很可能让系统或你的账号出问题。",
"title_en": "Recursively change owner of / or ~",
"desc_en": "Rewrites ownership of every file under the system or home directory — very likely to break the system or your account.",
"tools": [
"Bash"
],
"field": "command",
"pattern": "\\bchown\\s+(-R\\s+)?\\S+\\s+(/|~)(\\s|$)"
},
{
"id": "chgrp_root_recursive",
"risk": "high",
"action": "block",
"title": "递归更改根目录 / 家目录的所属组",
"desc": "同递归改所有者,作用于组。",
"title_en": "Recursively change group of / or ~",
"desc_en": "Same as the recursive owner change, applied to the group.",
"tools": [
"Bash"
],
"field": "command",
"pattern": "\\bchgrp\\s+(-R\\s+)?\\S+\\s+(/|~)(\\s|$)"
},
{
"id": "setuid_setgid_bit",
"risk": "high",
"action": "confirm",
"title": "给程序加 setuid / setgid 位",
"desc": "让这个程序以文件所有者(通常是 root)的身份运行,是经典的提权后门做法。",
"title_en": "Set the setuid / setgid bit",
"desc_en": "Makes the program run as the file's owner (usually root) — a classic privilege-escalation backdoor.",
"tools": [
"Bash"
],
"field": "command",
"pattern": "\\bchmod\\s+(-R\\s+)?\\S*[ug]\\+s\\b|\\bchmod\\s+(-R\\s+)?[0-7]?[42][0-7]{3}\\b"
},
{
"id": "chmod_recursive_generic",
"risk": "medium",
"action": "confirm",
"title": "递归修改权限",
"desc": "chmod -R 会改一整棵目录树的权限,确认范围是否只在项目里。",
"title_en": "Recursive permission change",
"desc_en": "chmod -R changes permissions on an entire directory tree; check that the scope stays inside the project.",
"tools": [
"Bash"
],
"field": "command",
"pattern": "\\bchmod\\s+-R\\b"
},
{
"id": "chmod_777_single_file",
"risk": "medium",
"action": "confirm",
"title": "把文件设成所有人可读写执行",
"desc": "777 权限过于宽松,看看是不是真的需要。",
"title_en": "Make a file world-readable/writable/executable",
"desc_en": "777 is far more permissive than almost anything needs; check whether it is really required.",
"tools": [
"Bash"
],
"field": "command",
"pattern": "\\bchmod\\s+777\\b"
},
{
"id": "fork_bomb",
"risk": "high",
"action": "block",
"title": "Fork 炸弹",
"desc": "无限自我复制的进程,会在几秒内耗尽系统资源。",
"title_en": "Fork bomb",
"desc_en": "A process that replicates itself endlessly, exhausting system resources within seconds.",
"tools": [
"Bash"
],
"field": "command",
"pattern": ":\\s*\\(\\s*\\)\\s*\\{[^}]*:\\s*\\|\\s*:[^}]*&[^}]*\\}\\s*;\\s*:"
},
{
"id": "user_account_management",
"risk": "high",
"action": "confirm",
"title": "增删改系统用户 / 修改密码",
"desc": "useradd、userdel、usermod、passwd 会改动这台机器上的账号。",
"title_en": "Add / remove / modify system users or passwords",
"desc_en": "useradd, userdel, usermod, passwd change the accounts on this machine.",
"tools": [
"Bash"
],
"field": "command",
"pattern": "\\b(useradd|userdel|usermod|adduser|deluser|passwd)\\b"
},
{
"id": "ssh_authorized_keys_bash_write",
"risk": "high",
"action": "block",
"title": "往 SSH 授权密钥 / 配置里写内容",
"desc": "往 authorized_keys 追加公钥 = 给某人这台机器的免密登录权限。",
"title_en": "Write to SSH authorized_keys / config",
"desc_en": "Appending a public key to authorized_keys grants someone passwordless login to this machine.",
"tools": [
"Bash"
],
"field": "command",
"pattern": ">>?\\s*~?/?(\\.ssh/authorized_keys|\\.ssh/id_\\w+|\\.ssh/config)\\b"
},
{
"id": "crontab_persistence",
"risk": "medium",
"action": "confirm",
"title": "添加定时任务",
"desc": "修改 crontab 或 /etc/cron,让某个命令以后定期自动运行——常见的驻留手法。",
"title_en": "Add a scheduled task",
"desc_en": "Edits crontab or /etc/cron so a command keeps running on a schedule — a common persistence technique.",
"tools": [
"Bash"
],
"field": "command",
"pattern": "\\bcrontab\\s+-[erl]\\b|>>?\\s*/etc/cron"
},
{
"id": "systemd_persistence",
"risk": "medium",
"action": "confirm",
"title": "启用 / 启动系统服务",
"desc": "systemctl enable / start 会让某个服务开机自启或立即运行。",
"title_en": "Enable / start a system service",
"desc_en": "systemctl enable / start makes a service start at boot or right now.",
"tools": [
"Bash"
],
"field": "command",
"pattern": "\\bsystemctl\\s+(enable|start)\\s+\\S+"
},
{
"id": "disable_security_controls",
"risk": "high",
"action": "block",
"title": "关闭安全防护",
"desc": "关掉 SELinux、防火墙,清空 iptables,或停掉安全相关服务。",
"title_en": "Disable security controls",
"desc_en": "Turns off SELinux or the firewall, flushes iptables, or stops security-related services.",
"tools": [
"Bash"
],
"field": "command",
"pattern": "\\bsetenforce\\s+0\\b|\\bufw\\s+disable\\b|\\biptables\\s+(-F|--flush)\\b|\\bsystemctl\\s+(stop|disable)\\s+(firewalld|ufw|apparmor)\\b"
},
{
"id": "kill_monitoring_process",
"risk": "high",
"action": "confirm",
"title": "结束 CC-Monitor 自身的进程",
"desc": "试图杀掉监控探针或 hook,等于把这个监控关掉。",
"title_en": "Kill CC-Monitor's own processes",
"desc_en": "Tries to kill the monitoring probe or hook — effectively switching this monitor off.",
"tools": [
"Bash"
],
"field": "command",
"pattern": "\\b(kill|pkill|killall)\\b[^\\n]*\\b(CC-Monitor-probe|CC-Monitor-hook|probe_linux\\.bt|probe_darwin\\.py|cc_monitor\\.probe|bpftrace)\\b"
},
{
"id": "process_kill",
"risk": "low",
"action": "log",
"title": "结束进程",
"desc": "kill / pkill / killall 结束进程,看一下目标是不是自己的进程。",
"title_en": "Kill a process",
"desc_en": "kill / pkill / killall terminates processes; check the target is one of yours.",
"tools": [
"Bash"
],
"field": "command",
"pattern": "\\b(kill|pkill|killall)\\b"
},
{
"id": "sudo_pip_install",
"risk": "high",
"action": "block",
"title": "用 sudo 往系统 Python 装包",
"desc": "会直接改系统级 Python,可能弄坏系统自带的工具;应该改用虚拟环境。",
"title_en": "sudo pip install into the system Python",
"desc_en": "Modifies the system-wide Python and can break OS tooling; use a virtualenv instead.",
"tools": [
"Bash"
],
"field": "command",
"pattern": "\\bsudo\\s+(python3?\\s+-m\\s+pip|pip3?)\\s+install\\b",
"match": "segment"
},
{
"id": "sudo_uv_pip_install",
"risk": "high",
"action": "block",
"title": "用 sudo 通过 uv 往系统 Python 装包",
"desc": "sudo uv pip install 会把包写进系统 Python,跟 sudo pip install 一样会污染发行版自己管理的目录。",
"title_en": "sudo uv pip install into the system Python",
"desc_en": "sudo uv pip install writes into the system Python, polluting distro-managed directories the same way sudo pip install does.",
"tools": [
"Bash"
],
"field": "command",
"pattern": "\\bsudo\\s+uv\\s+pip\\s+install\\b",
"match": "segment"
},
{
"id": "system_package_install",
"risk": "medium",
"action": "confirm",
"title": "系统包管理器安装 / 卸载软件",
"desc": "apt、yum、dnf、pacman、brew、port 会往系统里装或删软件。",
"title_en": "System package manager install / remove",
"desc_en": "apt, yum, dnf, pacman, brew, port install or remove software system-wide.",
"tools": [
"Bash"
],
"field": "command",
"pattern": "\\b(apt|apt-get)\\s+(install|remove|purge|autoremove)\\b|\\b(yum|dnf)\\s+(install|remove|erase)\\b|\\bpacman\\s+-(?-i:[A-Za-z]*[SRU][A-Za-z]*)\\b|\\bapk\\s+(add|del)\\b|\\bzypper\\s+(install|remove)\\b|\\bbrew\\s+(cask\\s+)?(install|reinstall|uninstall|remove|rm|upgrade|tap|untap|bundle)\\b|\\bport\\s+(-{1,2}[A-Za-z][\\w-]*(=\\S+|\\s+/\\S+)?\\s+)*(install|uninstall|upgrade|activate|deactivate|selfupdate|sync)\\b|\\bsnap\\s+(install|remove)\\b|\\bflatpak\\s+(install|uninstall)\\b|\\bdpkg\\s+(-i\\b|--install\\b)|\\brpm\\s+-(i|U|e)\\b|\\bemerge\\b|\\bnix-env\\s+-\\S*[ie]\\S*\\b|\\bnix\\s+profile\\s+(install|remove)\\b|\\bxbps-install\\b|\\bpkg\\s+(install|add|delete)\\b|\\bmas\\s+install\\b|\\beopkg\\s+(install|it)\\b",
"match": "segment"
},
{
"id": "sudo_usage",
"risk": "medium",
"action": "confirm",
"title": "以 root 权限执行命令",
"desc": "sudo 后面的命令会以管理员身份运行,看清它要做什么。",
"title_en": "Run a command as root",
"desc_en": "Whatever follows sudo runs with administrator privileges; read it carefully.",
"tools": [
"Bash"
],
"field": "command",
"pattern": "(^|;|&&|\\|\\|)\\s*sudo\\b",
"match": "segment"
},
{
"id": "su_pkexec_privilege_escalation",
"risk": "medium",
"action": "confirm",
"title": "切换到 root / 提权执行",
"desc": "su 或 pkexec 提权,之后的操作不再受普通用户权限限制。",
"title_en": "Switch to root / escalate privileges",
"desc_en": "su or pkexec escalates privileges; subsequent actions are no longer bound by normal user permissions.",
"tools": [
"Bash"
],
"field": "command",
"pattern": "(^|;|&&|\\|\\|)\\s*(su|pkexec)\\b",
"match": "segment"
},
{
"id": "pip_install_venv_context",
"risk": "low",
"action": "log",
"title": "在虚拟环境里 pip 安装",
"desc": "在 venv / conda 环境里装包,影响范围限于这个环境。",
"title_en": "pip install inside a virtualenv",
"desc_en": "Installs into a venv / conda environment; the impact is confined to that environment.",
"tools": [
"Bash"
],
"field": "command",
"pattern": "(?=.*\\b(pip3?\\s+install|python3?\\s+-m\\s+pip\\s+install)\\b)(?=.*(venv|virtualenv|\\.venv|conda\\s+activate|pipx\\s+install|pipenv\\s+install|poetry\\s+(add|install)|--user\\b))"
},
{
"id": "pip_install_no_venv",
"risk": "high",
"action": "confirm",
"title": "不在虚拟环境里 pip 安装",
"desc": "没有激活虚拟环境就 pip install,会装到用户级或系统级 Python 里。",
"title_en": "pip install outside a virtualenv",
"desc_en": "pip install with no virtualenv active installs into the user- or system-level Python.",
"tools": [
"Bash"
],
"field": "command",
"pattern": "\\b(pip3?\\s+install|python3?\\s+-m\\s+pip\\s+install)\\b",
"match": "segment"
},
{
"id": "uv_pip_install_system",
"risk": "high",
"action": "confirm",
"title": "uv 装到系统/用户级 Python",
"desc": "uv pip install 默认只往激活的虚拟环境里装,加了 --system 或 --break-system-packages 就绕过这层保护,直接写系统或用户级 Python。",
"title_en": "uv installing into the system/user Python",
"desc_en": "uv pip install normally only touches the active virtualenv; --system or --break-system-packages bypasses that and writes into the system or user Python.",
"tools": [
"Bash"
],
"field": "command",
"pattern": "^uv\\s+pip\\s+install\\b.*(?:--system|--break-system-packages)\\b",
"match": "segment"
},
{
"id": "uv_pip_install",
"risk": "low",
"action": "log",
"title": "uv pip 安装",
"desc": "用 uv 的 pip 兼容接口装 Python 包。uv 在没有激活虚拟环境时会直接报错而不是装进系统,所以默认只记录不打扰。",
"title_en": "uv pip install",
"desc_en": "Installing Python packages through uv's pip-compatible interface. uv errors out rather than installing system-wide when no virtualenv is active, so this is logged only.",
"tools": [
"Bash"
],
"field": "command",
"pattern": "^uv\\s+pip\\s+(?:install|sync)\\b",
"match": "segment"
},
{
"id": "uv_project_install",
"risk": "low",
"action": "log",
"title": "uv 项目/工具安装",
"desc": "uv add / uv sync / uv tool install 这类安装:依赖装进项目的 .venv,工具装进 uv 自己的目录,都不碰系统 Python。",
"title_en": "uv project/tool install",
"desc_en": "uv add / uv sync / uv tool install: dependencies go into the project's .venv and tools into uv's own directory, neither touching the system Python.",
"tools": [
"Bash"
],
"field": "command",
"pattern": "^uv\\s+(?:add|sync|tool\\s+install)\\b",
"match": "segment"
},
{
"id": "npm_global_install",
"risk": "medium",
"action": "confirm",
"title": "npm 全局安装",
"desc": "npm install -g 装到系统级 node_modules,所有项目都会受影响。",
"title_en": "npm global install",
"desc_en": "npm install -g installs into the system-wide node_modules, affecting every project.",
"tools": [
"Bash"
],
"field": "command",
"pattern": "\\b(sudo\\s+)?npm\\s+(install|i)\\s+.*(-g\\b|--global\\b)",
"match": "segment"
},
{
"id": "npm_local_install",
"risk": "low",
"action": "log",
"title": "npm 项目内安装",
"desc": "在当前项目里 npm install。",
"title_en": "npm install in the project",
"desc_en": "npm install scoped to the current project.",
"tools": [
"Bash"
],
"field": "command",
"pattern": "\\b(sudo\\s+)?npm\\s+(install|i)\\b",
"match": "segment"
},
{
"id": "js_package_install_global",
"risk": "medium",
"action": "confirm",
"title": "JS 包管理器全局安装",
"desc": "yarn/pnpm/bun/deno 往全局装包,装完在任何目录都能直接调用,影响范围不限于当前项目。",
"title_en": "Global install via a JS package manager",
"desc_en": "yarn/pnpm/bun/deno installing globally: the package becomes callable from any directory, not just this project.",
"tools": [
"Bash"
],
"field": "command",
"pattern": "\\byarn\\s+global\\s+add\\b|\\b(pnpm|bun)\\s+(add|install|i)\\b[^|;&]*(-g\\b|--global\\b)|\\bdeno\\s+install\\b",
"match": "segment"
},
{
"id": "js_package_install",
"risk": "low",
"action": "log",
"title": "JS 包管理器安装依赖",
"desc": "yarn/pnpm/bun 装项目依赖,或 npm ci 按 lock 文件重装。装进项目的 node_modules,不出项目目录。",
"title_en": "JS package manager installing dependencies",
"desc_en": "yarn/pnpm/bun installing project dependencies, or npm ci reinstalling from the lockfile. Everything lands in the project's node_modules.",
"tools": [
"Bash"
],
"field": "command",
"pattern": "\\b(yarn|pnpm|bun)\\s+(add|install|i)\\b|\\bnpm\\s+ci\\b|\\bdeno\\s+add\\b|\\byarn\\s*$",
"match": "segment"
},
{
"id": "python_package_install_other",
"risk": "low",
"action": "log",
"title": "其它 Python 包管理器安装",
"desc": "conda/mamba/poetry/pipenv/pipx/pdm/rye 装 Python 包。这些都装进各自管理的环境,不动系统 Python。",
"title_en": "Install via another Python package manager",
"desc_en": "conda/mamba/poetry/pipenv/pipx/pdm/rye installing Python packages. Each installs into the environment it manages, leaving the system Python alone.",
"tools": [
"Bash"
],
"field": "command",
"pattern": "\\b(conda|mamba|micromamba)\\s+(install|env\\s+(create|update))\\b|\\bpoetry\\s+(add|install|update)\\b|\\bpipenv\\s+(install|update|sync)\\b|\\bpipx\\s+(install|inject|upgrade)\\b|\\bpdm\\s+(add|install|sync)\\b|\\brye\\s+(add|sync)\\b|\\bhatch\\s+env\\s+create\\b",
"match": "segment"
},
{
"id": "python_legacy_install",
"risk": "medium",
"action": "confirm",
"title": "用过时方式安装 Python 包",
"desc": "easy_install 和 python setup.py install 会直接往 site-packages 写,绕过 pip 的依赖解析和卸载记录,装完很难干净移除。",
"title_en": "Installing a Python package the legacy way",
"desc_en": "easy_install and python setup.py install write straight into site-packages, bypassing pip's dependency resolution and uninstall records, which makes them hard to remove cleanly.",
"tools": [
"Bash"
],
"field": "command",
"pattern": "\\beasy_install\\b|\\bpython3?\\s+setup\\.py\\s+(install|develop)\\b",
"match": "segment"
},
{
"id": "toolchain_install",
"risk": "low",
"action": "log",
"title": "工具链 / 版本管理器安装",
"desc": "asdf/nvm/pyenv/rustup/mise 这类装语言运行时或工具链。装进家目录,通常还会改 shell 配置文件。",
"title_en": "Toolchain / version manager install",
"desc_en": "asdf/nvm/pyenv/rustup/mise installing a language runtime or toolchain. These write into the home directory and usually touch shell rc files too.",
"tools": [
"Bash"
],
"field": "command",
"pattern": "\\b(asdf|nvm|pyenv|rbenv|nodenv|goenv|tfenv|jenv|volta|mise|rtx|gvm|ghcup)\\s+(install|use|add)\\b|\\brustup\\s+(toolchain\\s+install|component\\s+add|target\\s+add|install|update)\\b|\\bsdk\\s+install\\b",
"match": "segment"
},
{
"id": "container_image_pull",
"risk": "low",
"action": "log",
"title": "拉取容器镜像 / 部署 Chart",
"desc": "docker/podman 拉镜像,或 helm 装 chart。拉下来的是别人打好的完整文件系统,内容不受本机规则约束。",
"title_en": "Pulling a container image / installing a chart",
"desc_en": "docker/podman pulling an image, or helm installing a chart. What comes down is someone else's prebuilt filesystem, whose contents this machine's rules never see.",
"tools": [
"Bash"
],
"field": "command",
"pattern": "\\b(docker|podman|nerdctl)\\s+(pull|image\\s+pull)\\b|\\bdocker\\s+compose\\s+pull\\b|\\bhelm\\s+(install|upgrade)\\b|\\bskopeo\\s+copy\\b",
"match": "segment"
},
{
"id": "editor_plugin_install",
"risk": "low",
"action": "log",
"title": "编辑器 / CLI 插件安装",
"desc": "给 VS Code、gh、kubectl、Claude Code 装插件或 MCP server。插件拿到的权限跟宿主程序一样大。",
"title_en": "Editor / CLI plugin install",
"desc_en": "Installing a plugin or MCP server into VS Code, gh, kubectl or Claude Code. A plugin runs with the same privileges as its host.",
"tools": [
"Bash"
],
"field": "command",
"pattern": "\\b(code|codium|cursor)\\s+--install-extension\\b|\\bgh\\s+extension\\s+install\\b|\\bkubectl\\s+krew\\s+install\\b|\\bkrew\\s+install\\b|\\bhelm\\s+plugin\\s+install\\b|\\bclaude\\s+mcp\\s+add\\b",
"match": "segment"
},
{
"id": "source_build_install",
"risk": "low",
"action": "log",
"title": "从源码编译安装",
"desc": "make install / cmake --install 会把编译产物copy到安装前缀下,目标路径写在构建脚本里,命令文本上看不出来装到了哪。",
"title_en": "Installing from a source build",
"desc_en": "make install / cmake --install copies build output into the install prefix. The destination lives in the build script, so the command text alone never shows where it lands.",
"tools": [
"Bash"
],
"field": "command",
"pattern": "\\bmake\\b[^|;&]*\\binstall\\b|\\bcmake\\s+--install\\b|\\bninja\\s+install\\b|\\bcheckinstall\\b",
"match": "segment"
},
{
"id": "package_install_other",
"risk": "low",
"action": "log",
"title": "其它包管理器安装",
"desc": "gem、cargo、go install、composer 等。",
"title_en": "Other package manager install",
"desc_en": "gem, cargo, go install, composer and similar.",
"tools": [
"Bash"
],
"field": "command",
"pattern": "\\bgem\\s+install\\b|\\bcargo\\s+install\\b|\\bgo\\s+install\\b|\\bcomposer\\s+(require|global\\s+require)\\b|\\bbundle\\s+install\\b|\\bcargo\\s+binstall\\b|\\bgo\\s+get\\b|\\bcomposer\\s+install\\b|\\bdotnet\\s+(add\\s+package|tool\\s+install)\\b|\\bcabal\\s+install\\b|\\bstack\\s+install\\b|\\bcpanm?\\b|\\bluarocks\\s+install\\b|\\bnimble\\s+install\\b|\\bmix\\s+(deps\\.get|archive\\.install)\\b|\\b(dart|flutter)\\s+pub\\s+(get|add|global\\s+activate)\\b|\\bswift\\s+package\\s+(resolve|update)\\b|\\bpub\\s+global\\s+activate\\b|\\b(R|Rscript)\\b[^|;&]*install\\.packages|\\bjulia\\b[^|;&]*Pkg\\.add",
"match": "segment"
},
{
"id": "git_force_push",
"risk": "medium",
"action": "confirm",
"title": "git 强制推送",
"desc": "git push --force 会覆盖远程分支的历史,别人已经拉取的提交可能丢失。确认分支和远程无误。",
"title_en": "git force push",
"desc_en": "git push --force overwrites the remote branch history; commits others already pulled may be lost. Verify the branch and remote.",
"tools": [
"Bash"
],
"field": "command",
"pattern": "\\bgit\\s+push\\b.*(--force|-f)\\b"
},
{
"id": "git_hard_reset_clean",
"risk": "medium",
"action": "confirm",
"title": "git 硬重置 / 清理未跟踪文件",
"desc": "reset --hard 或 clean -fd 会丢掉未提交的改动和未跟踪的文件,不可恢复。",
"title_en": "git hard reset / clean untracked files",
"desc_en": "reset --hard or clean -fd throws away uncommitted changes and untracked files — irreversibly.",
"tools": [
"Bash"
],
"field": "command",
"pattern": "\\bgit\\s+reset\\s+--hard\\b|\\bgit\\s+clean\\s+-[a-zA-Z]*f[a-zA-Z]*d?[a-zA-Z]*\\b"
},
{
"id": "git_hooks_persistence",
"risk": "medium",
"action": "confirm",
"title": "修改 git hooks 路径 / URL 重写规则",
"desc": "改 core.hooksPath 或 url.insteadOf,可以让以后每次 git 操作都悄悄执行别的东西。",
"title_en": "Change git hooks path / URL rewrite",
"desc_en": "Changing core.hooksPath or url.insteadOf can make every future git operation silently run something else.",
"tools": [
"Bash"
],
"field": "command",
"pattern": "\\bgit\\s+config\\b[^\\n]*\\b(core\\.hooksPath|url\\.\\S+\\.insteadOf)\\b|>>?\\s*\\.git/hooks/"
},
{
"id": "history_tampering",
"risk": "medium",
"action": "confirm",
"title": "清除 / 篡改命令历史",
"desc": "删掉 shell 的历史记录,常用于抹掉痕迹。",
"title_en": "Clear / tamper with shell history",
"desc_en": "Deletes the shell history — commonly done to erase traces.",
"tools": [
"Bash"
],
"field": "command",
"pattern": "\\bhistory\\s+-c\\b|>\\s*~?/?\\.(bash|zsh)_history\\b|\\brm\\s+(-\\S+\\s+)*~?/\\.(bash|zsh)_history\\b|\\brm\\s+(-\\S+\\s+)*[^\\n|;&]*\\.(zsh|bash)_sessions/"
},
{
"id": "history_read",
"risk": "low",
"action": "log",
"title": "读取命令历史",
"desc": "读 .bash_history / .zsh_history 等,里面可能有你敲过的密码和密钥。",
"title_en": "Read shell history",
"desc_en": "Reads .bash_history / .zsh_history etc., which may contain passwords and keys you typed.",
"tools": [
"Bash"
],
"field": "command",
"pattern": "\\.(bash|zsh|python|mysql|psql|node_repl|sqlite|irb)_history\\b|\\.zhistory\\b|\\.(zsh|bash)_sessions/|/\\.history\\b|\\$\\{?HISTFILE\\b|\\.claude/history\\.jsonl\\b|(^|[;&|(`])\\s*(history|fc\\s+-[a-zA-Z]*l[a-zA-Z]*)\\b(?!\\s*-c\\b)"
},
{
"id": "history_file_read",
"risk": "low",
"action": "log",
"title": "读取历史记录文件",
"desc": "用文件工具读 shell 历史记录,同上。",
"title_en": "Read a history file",
"desc_en": "Reads shell history via a file tool; same concern as above.",
"tools": [
"Read",
"Grep"
],
"field": "file_path",
"pattern": "\\.(bash|zsh|python|mysql|psql|node_repl|sqlite|irb)_history\\b|\\.zhistory\\b|\\.(zsh|bash)_sessions/|/\\.history\\b|\\.claude/history\\.jsonl\\b"
},
{
"id": "db_destructive_command",
"risk": "high",
"action": "confirm",
"title": "数据库破坏性操作",
"desc": "DROP、DELETE、TRUNCATE、FLUSHALL 等会删数据。",
"title_en": "Destructive database command",
"desc_en": "DROP, DELETE, TRUNCATE, FLUSHALL and similar delete data.",
"tools": [
"Bash"
],
"field": "command",
"pattern": "\\b(mysql|psql|redis-cli|mongo|mongosh|sqlite3)\\b[^\\n|;&]*\\b(DROP|DELETE|TRUNCATE|FLUSHALL|FLUSHDB)\\b"
},
{
"id": "db_arbitrary_file_write",
"risk": "high",
"action": "confirm",
"title": "通过数据库写任意文件",
"desc": "用 OUTFILE / DUMPFILE 导出或改 general_log_file 路径,让数据库往磁盘写文件,常被用来落地 webshell。",
"title_en": "Arbitrary file write via the database",
"desc_en": "OUTFILE / DUMPFILE exports or redirecting general_log_file make the database write files to disk — often used to drop a webshell.",
"tools": [
"Bash"
],
"field": "command",
"pattern": "\\bINTO\\s+(OUTFILE|DUMPFILE)\\b|\\bgeneral_log_file\\s*=\\s*['\"]?/|\\bSET\\s+(GLOBAL\\s+)?general_log\\s*=\\s*['\"]?ON\\b"
},
{
"id": "docker_privileged_or_host_mount",
"risk": "high",
"action": "confirm",
"title": "特权容器 / 挂载宿主机根目录",
"desc": "--privileged、挂载 / 或 docker.sock,容器里可以完全控制宿主机。",
"title_en": "Privileged container / host root mount",
"desc_en": "--privileged, mounting / or docker.sock gives the container full control of the host.",
"tools": [
"Bash"
],
"field": "command",
"pattern": "\\bdocker\\s+run\\b[^\\n]*(--privileged\\b|-v\\s+/:/|docker\\.sock)"
},
{
"id": "sensitive_file_write",
"risk": "high",
"action": "block",
"title": "写入 SSH 密钥 / 云凭据 / .env 等敏感文件",
"desc": "改这些文件等于改你的身份凭证。",
"title_en": "Write to SSH keys / cloud credentials / .env",
"desc_en": "Modifying these files is modifying your identity credentials.",
"tools": [
"Write",
"Edit",
"NotebookEdit"
],
"field": "file_path",
"pattern": "(\\.ssh/|\\.aws/credentials|\\.env$|id_rsa|id_ed25519|\\.pem$|\\.p12$|known_hosts$)"
},
{
"id": "shell_rc_write",
"risk": "medium",
"action": "confirm",
"title": "修改 shell 启动配置",
"desc": "改 .bashrc / .zshrc / .profile,里面的内容以后每次开终端都会自动执行。",
"title_en": "Modify shell startup files",
"desc_en": "Edits .bashrc / .zshrc / .profile — whatever goes in there runs every time a terminal opens.",
"tools": [
"Write",
"Edit"
],
"field": "file_path",
"pattern": "(\\.bashrc|\\.zshrc|\\.profile|\\.bash_profile|\\.zprofile)$"
},
{
"id": "claude_config_tamper",
"risk": "high",
"action": "confirm",
"title": "修改 Claude Code 自身配置",
"desc": "改 settings.json / hooks / CLAUDE.md / .mcp.json,能改变 Claude 的权限和行为,甚至关掉这个监控。",
"title_en": "Modify Claude Code's own configuration",
"desc_en": "Editing settings.json / hooks / CLAUDE.md / .mcp.json can change Claude's permissions and behavior — even disable this monitor.",
"tools": [
"Write",
"Edit",
"NotebookEdit"
],
"field": "file_path",
"pattern": "(^|/)\\.claude/settings(\\.local)?\\.json$|(^|/)\\.claude/hooks/|(^|/)CLAUDE\\.md$|(^|/)\\.mcp\\.json$|(^|/)\\.claude/skills/"
},
{
"id": "git_hooks_file_write",
"risk": "medium",
"action": "confirm",
"title": "写入 git hooks 脚本",
"desc": ".git/hooks 里的脚本会在 commit / push 时自动执行。",
"title_en": "Write a git hook script",
"desc_en": "Scripts under .git/hooks run automatically on commit / push.",
"tools": [
"Write",
"Edit",
"NotebookEdit"
],
"field": "file_path",
"pattern": "(^|/)\\.git/hooks/"
},
{
"id": "secret_pattern_in_write",
"risk": "high",
"action": "confirm",
"title": "写入的内容里含密钥 / Token",
"desc": "要写进文件的内容里出现私钥、AK/SK、API Token 等格式,可能是在把密钥硬编码进代码。",
"title_en": "Secret / token in written content",
"desc_en": "The content about to be written contains a private key, AK/SK or API token pattern — possibly hard-coding a secret into the code.",
"tools": [
"Write",
"Edit",
"NotebookEdit"
],
"field": "content",
"pattern": "-----BEGIN (RSA |EC |OPENSSH |DSA |PGP )?PRIVATE KEY-----|\\bAKIA[0-9A-Z]{16}\\b|\\bASIA[0-9A-Z]{16}\\b|\\bgh[pousr]_[A-Za-z0-9]{36,}\\b|\\bgithub_pat_[A-Za-z0-9_]{20,}\\b|\\bsk-ant-[A-Za-z0-9_-]{20,}\\b|\\bsk-proj-[A-Za-z0-9_-]{20,}\\b|\\bsk-[A-Za-z0-9]{32,48}\\b|\\bxox[baprs]-[A-Za-z0-9-]{10,}\\b|\\bAIza[0-9A-Za-z_-]{35}\\b|\\bnpm_[A-Za-z0-9]{36}\\b|\\bsk_live_[0-9a-zA-Z]{24,}\\b|\\bLTAI[0-9A-Za-z]{12,20}\\b|\\bAKID[0-9A-Za-z]{32,}\\b|\\bglpat-[0-9A-Za-z_-]{20,}\\b|gitee\\.com[^\\n]{0,80}\\b[0-9a-f]{40}\\b|\\bPrivateKey\\s*=\\s*[A-Za-z0-9+/]{40,}={0,2}|\\b(password|passwd|pwd|secret|api[_-]?key|access[_-]?key)\\s*[:=]\\s*['\"][^'\"\\s]{6,}['\"]"
},
{
"id": "pii_pattern_in_write",
"risk": "medium",
"action": "log",
"title": "写入的内容里含个人信息",
"desc": "身份证号、手机号、邮箱等个人信息。",
"title_en": "PII in written content",
"desc_en": "ID numbers, phone numbers, email addresses and similar personal data.",
"tools": [
"Write",
"Edit",
"NotebookEdit"
],
"field": "content",
"pattern": "\\b[1-9]\\d{5}(18|19|20)\\d{2}(0[1-9]|1[0-2])(0[1-9]|[12]\\d|3[01])\\d{3}[\\dXx]\\b|\\b1[3-9]\\d{9}\\b|\\b[a-zA-Z0-9._%+-]+@[a-zA-Z0-9.-]+\\.[a-zA-Z]{2,}\\b"
},
{
"id": "webshell_pattern_in_write",
"risk": "high",
"action": "block",
"title": "写入 Webshell 代码",
"desc": "把 HTTP 请求参数(POST / GET)直接交给 eval / assert 执行——一句话木马的经典特征。",
"title_en": "Writing webshell code",
"desc_en": "Request parameters (POST / GET) passed straight into eval / assert — the classic one-liner webshell signature.",
"tools": [
"Write",
"Edit",
"NotebookEdit"
],
"field": "content",
"pattern": "eval\\s*\\(\\s*\\$_(POST|GET|REQUEST|COOKIE)\\s*\\[|assert\\s*\\(\\s*\\$_(POST|GET|REQUEST|COOKIE)\\s*\\[|system\\s*\\(\\s*\\$_(POST|GET|REQUEST)\\s*\\[|eval\\s+request\\s*\\(|Runtime\\.getRuntime\\(\\)\\.exec\\s*\\(\\s*request\\.getParameter"
},
{
"id": "dynamic_exec_in_write",
"risk": "medium",
"action": "log",
"title": "写入动态执行代码",
"desc": "eval / exec / os.system / subprocess shell=True,看一下是否必要。",
"title_en": "Dynamic code execution in written content",
"desc_en": "eval / exec / os.system / subprocess shell=True; check whether it is really needed.",
"tools": [
"Write",
"Edit",
"NotebookEdit"
],
"field": "content",
"pattern": "\\beval\\s*\\(|\\bexec\\s*\\(|\\bos\\.system\\s*\\(|\\bsubprocess\\.(Popen|call|run)\\s*\\([^)]*shell\\s*=\\s*True|\\bnew Function\\s*\\(|\\bchild_process\\.exec\\s*\\("
},
{
"id": "db_arbitrary_file_write_content",
"risk": "medium",
"action": "confirm",
"title": "写入的内容含数据库写文件语句",
"desc": "文件内容里出现 OUTFILE / DUMPFILE 导出或 general_log_file 改路径这类让数据库往磁盘写文件的语句。",
"title_en": "Database file-write statement in written content",
"desc_en": "The file content contains OUTFILE / DUMPFILE exports or general_log_file redirection — statements that make a database write to disk.",
"tools": [
"Write",
"Edit",
"NotebookEdit"
],
"field": "content",
"pattern": "\\bINTO\\s+(OUTFILE|DUMPFILE)\\b|\\bgeneral_log_file\\s*=\\s*['\"]?/|\\bSET\\s+(GLOBAL\\s+)?general_log\\s*=\\s*['\"]?ON\\b"
},
{
"id": "crypto_miner_pool_domain_write",
"risk": "medium",
"action": "confirm",
"title": "写入的内容含矿池地址",
"desc": "文件内容里出现矿池域名或 stratum 协议。",
"title_en": "Mining-pool address in written content",
"desc_en": "The file content references a mining-pool domain or the stratum protocol.",
"tools": [
"Write",
"Edit",
"NotebookEdit"
],
"field": "content",
"pattern": "\\bstratum\\+(tcp|ssl|tcps)://|\\b(pool\\.minergate\\.com|pool\\.minexmr\\.com|opmoner\\.com|crypto-pool\\.fr|backup-pool\\.com|monerohash\\.com|poolto\\.be|xminingpool\\.com|prohash\\.net|dwarfpool\\.com|crypto-pools\\.org|monero\\.net|hashinvest\\.net|moneropool\\.com|xmrpool\\.eu|ppxxmr\\.com|alimabi\\.cn|aeon-pool\\.com)\\b"
},
{
"id": "cloud_vpn_config_write",
"risk": "high",
"action": "confirm",
"title": "写入 VPN / 云 CLI 配置",
"desc": ".ovpn、wireguard、kubeconfig、阿里云 / 腾讯云凭据目录。",
"title_en": "Write VPN / cloud CLI config",