w-32768 / PHP-Webshell-Detection-via-Opcode-Analysis

This repository detects PHP webshells by converting PHP code to opcode and analyzing it using Opcode Double-Tuples (ODTs), which combine opcode instructions and operands. The opcode undergoes advanced processing, including filtering, decoding, and semantic preservation, to identify malicious patterns effectively.
40Updated last month

Alternatives and similar repositories for PHP-Webshell-Detection-via-Opcode-Analysis:

Users that are interested in PHP-Webshell-Detection-via-Opcode-Analysis are comparing it to the libraries listed below