Laravel Scalpel: Scan for Filesystem Intrusion Evidence | Mohamed Said       [Skip to content](#main)  [ ![](https://cdn.msaied.com/01KT78WE565VEMM3PSNQAAB0MH.png) Mohamed SaidLaravel Backend Engineer ](https://www.msaied.com/public) - [Home](https://www.msaied.com/public)
- [Projects](https://www.msaied.com/public/projects)
- [Articles](https://www.msaied.com/public/articles)
- [Certificates](https://www.msaied.com/public/certificates)
- [About](https://www.msaied.com/public#about)

           [  Contact](https://www.msaied.com/public#contact) Menu 

Menu
----

Close 

 - [HomeStart here](https://www.msaied.com/public)
- [ProjectsCase studies](https://www.msaied.com/public/projects)
- [ArticlesEngineering notes](https://www.msaied.com/public/articles)
- [CertificatesCredentials](https://www.msaied.com/public/certificates)
- [AboutHow I work](https://www.msaied.com/public#about)
- [ContactGet in touch](https://www.msaied.com/public#contact)

  [Start a conversation](https://www.msaied.com/public#contact) [WhatsApp](https://wa.me/201094619204) [Email](mailto:hello@msaied.com) 

 1. [Home](https://www.msaied.com/public)
2. /
3. [Articles](https://www.msaied.com/public/articles)
4. /
5. [Laravel](https://www.msaied.com/public/articles?category=laravel)
6. /
7. Laravel Scalpel: Filesystem Intrusion Evidence Scanner for Laravel Apps

   [Laravel](https://www.msaied.com/public/articles?category=laravel) [Composer Pacakge](https://www.msaied.com/public/articles?category=composer-pacakge) 

 Laravel Scalpel: Filesystem Intrusion Evidence Scanner for Laravel Apps
========================================================================

 Laravel Scalpel is a post-compromise scanner that checks your deployed application's filesystem for rogue PHP files, obfuscated backdoors, tampered server directives, and changes from a trusted baseline.

 ![](https://cdn.msaied.com/01M22N44A70A5MC2S599JP0MPH.webp) [Mohamed Said](https://www.msaied.com/public#person) Published 17 Sep 2026 · Updated 17 Sep 2026 · 4 min read

ShareCopy linkCopied

 ![Laravel Scalpel: Filesystem Intrusion Evidence Scanner for Laravel Apps](https://cdn.msaied.com/675/406b0f123858892b97052502c0020eac.png) 

  On this page +1. [What Is Laravel Scalpel?](#what-is-laravel-scalpel)
2. [The Six Built-in Scanners](#the-six-built-in-scanners)
3. [Structural Scanner](#structural-scanner)
4. [Obfuscated-Code Scanner](#obfuscated-code-scanner)
5. [.htaccess Scanner](#htaccess-scanner)
6. [.user.ini Scanner](#userini-scanner)
7. [Environment Scanner](#environment-scanner)
8. [Baseline Diff Scanner](#baseline-diff-scanner)
9. [Creating and Using a Baseline](#creating-and-using-a-baseline)
10. [Fast Mode vs. Strict Mode](#fast-mode-vs-strict-mode)
11. [Signed Baselines](#signed-baselines)
12. [Running Selective Scans and CI Integration](#running-selective-scans-and-ci-integration)
13. [Installation](#installation)
14. [Key Takeaways](#key-takeaways)

 What Is Laravel Scalpel?
------------------------

[Laravel Scalpel](https://github.com/hryagstn/laravel-scalpel) is an intrusion evidence scanner built by Harry Agustiana. Unlike tools such as Ward or Checkpoint—which audit source code and dependencies for known vulnerabilities—Scalpel focuses on a different question: **have files in your deployed application already been added, changed, or removed?**

It runs as a set of Artisan commands inside a Laravel application and requires PHP 8.2+ with Laravel 10 through 13.

The Six Built-in Scanners
-------------------------

Running `php artisan scalpel:scan` executes six scanners by default.

### Structural Scanner

Looks for executable PHP files in directories where PHP should not appear—`public/` and `storage/` by default. It catches `.php`, `.phtml`, `.pht`, `.phar`, and double-extension files such as `shell.php.jpg`. Known-good paths like `public/index.php` and compiled views are allow-listed by default.

### Obfuscated-Code Scanner

Checks PHP files for common backdoor patterns: `eval(base64_decode(...))`, compressed payload execution, dynamic function calls, direct evaluation of request input, and long encoded strings. Individual patterns can be disabled in `config/scalpel.php` if legitimate code triggers a false positive.

### .htaccess Scanner

Flags handler and MIME-type mappings that allow the web server to execute Python, Perl, or CGI scripts, as well as `Options +ExecCGI`, external-URL rewrite rules, and directives like `auto_prepend_file`.

### .user.ini Scanner

Reports per-directory PHP directives including `auto_prepend_file`, `auto_append_file`, `include_path`, and `disable_functions`—all of which an attacker can exploit to run hidden code on every request.

### Environment Scanner

Checks for a missing, empty, or world-readable `.env` file, a `.env` placed under `public/`, an empty `APP_KEY`, key mismatches against `.env.example`, and `APP_DEBUG=true` in production.

### Baseline Diff Scanner

Compares current files against a saved SHA-256 snapshot and reports added, modified, and deleted files.

Creating and Using a Baseline
-----------------------------

```bash
# Record a trusted snapshot
php artisan scalpel:baseline

# Compare current files against it
php artisan scalpel:diff

```

Create the baseline only when the application is in a state you trust. After each deployment, the recommended workflow is:

```bash
php artisan optimize
php artisan scalpel:baseline --force

```

The `vendor/` directory is excluded from content scans but included in baseline comparisons, so a file injected into an installed package still appears in the diff.

### Fast Mode vs. Strict Mode

By default, Scalpel hashes every file on each run (strict mode). The `--fast` flag skips re-hashing when file size and modification time are unchanged—useful for large codebases, but it can miss a tampered file if an attacker preserves both attributes.

### Signed Baselines

Set `SCALPEL_SIGNING_ENABLED=true` and provide a dedicated `SCALPEL_SIGNING_KEY` (not your `APP_KEY`) to HMAC-sign baselines and JSON reports. The diff command verifies the signature before use and raises a `CRITICAL` finding if it is invalid or missing.

Running Selective Scans and CI Integration
------------------------------------------

```bash
# Run only specific scanners
php artisan scalpel:scan --only=structural,obfuscated

# Output SARIF for CI and fail on MEDIUM or higher
php artisan scalpel:scan --format=sarif --fail-on=MEDIUM

```

Exit codes: `0` = clean, `1` = finding at or above `--fail-on` severity, `2` = findings below threshold or incomplete scan.

After each scan or diff, Scalpel dispatches a `ScanFinished` event containing findings, command name, and duration in milliseconds—making it straightforward to route alerts to Slack, email, or a webhook without parsing CLI output.

**Note for CI pipelines:** `php artisan optimize` compiles views under `storage/framework/views`. The obfuscated-code scanner reads those generated files and can produce many false positives. Add `storage/framework/views` to `content_scan_excluded_paths` or run `optimize:clear` before scanning.

Installation
------------

```bash
composer require hryagstn/laravel-scalpel
php artisan vendor:publish --tag=scalpel-config

```

Key Takeaways
-------------

- Scalpel detects **post-compromise evidence**; it is not a firewall or WAF.
- Six scanners cover structural anomalies, obfuscated code, `.htaccess`/`.user.ini` tampering, environment issues, and baseline drift.
- Signed baselines add tamper detection but cannot protect against an attacker who can read the signing key.
- CI-friendly output formats (JSON, SARIF, GitHub Actions annotations) and configurable `--fail-on` severity make it easy to integrate into deployment pipelines.
- The scanner runs with the same permissions as the application—use external scan triggers and read-only code directories for stronger guarantees.

[Source: Laravel News — Laravel Scalpel Scans for Filesystem Intrusion Evidence](https://laravel-news.com/laravel-scalpel)

- [security](https://www.msaied.com/public/articles?search=security)
- [laravel](https://www.msaied.com/public/articles?search=laravel)
- [php](https://www.msaied.com/public/articles?search=php)
- [intrusion-detection](https://www.msaied.com/public/articles?search=intrusion-detection)
- [filesystem](https://www.msaied.com/public/articles?search=filesystem)
- [composer-package](https://www.msaied.com/public/articles?search=composer-package)

 Frequently asked questions 
---------------------------

  How is Laravel Scalpel different from other Laravel security tools like Ward or Checkpoint?Ward and Checkpoint inspect source code, configuration, and dependencies for known vulnerabilities before deployment. Scalpel is a post-compromise tool: it scans a deployed application's filesystem for evidence that files have already been added, changed, or removed by an attacker.

   When should I create a Scalpel baseline, and how do I keep it current?Create the baseline only when the application is in a state you trust. After every deployment, run `php artisan optimize` followed by `php artisan scalpel:baseline --force` to replace the old snapshot. Until a baseline exists, scans will report a MEDIUM finding prompting you to create one.

   Can Scalpel produce false positives from Laravel's compiled views?Yes. Running `php artisan optimize` compiles views under `storage/framework/views`, and the obfuscated-code scanner reads those files, potentially generating many MEDIUM and HIGH findings. To avoid this, add `storage/framework/views` to `content\_scan\_excluded\_paths` in `config/scalpel.php`, or run `php artisan optimize:clear` before scanning.

   ![Mohamed Said](https://cdn.msaied.com/01M22N44A70A5MC2S599JP0MPH.webp)About the author
----------------

[Mohamed Said](https://www.msaied.com/public#person)Senior Backend Engineer specializing in Laravel, scalable SaaS platforms, APIs, and cloud infrastructure. I build secure, high-performance web applications that help businesses grow.

[About](https://www.msaied.com/public#about) [GitHub ↗](https://github.com/EG-Mohamed) [LinkedIn ↗](https://www.linkedin.com/in/msaiedm/) [WhatsApp ↗](https://wa.me/201094619204) [Email Address ↗](mailto:hello@msaied.com) [My CV ↗](https://drive.google.com/file/u/0/d/1MF20IPRJyzfy32mhEutjL5EpSls0w2Q8/view)  

   [Previous articleMercure Broadcasting in Laravel 13.32](https://www.msaied.com/public/articles/mercure-broadcasting-in-laravel-1332) [Next articleInertia DevTools Now Available for Firefox](https://www.msaied.com/public/articles/inertia-devtools-now-available-for-firefox)  

   On this page
-------------

1. [What Is Laravel Scalpel?](#what-is-laravel-scalpel)
2. [The Six Built-in Scanners](#the-six-built-in-scanners)
3. [Structural Scanner](#structural-scanner)
4. [Obfuscated-Code Scanner](#obfuscated-code-scanner)
5. [.htaccess Scanner](#htaccess-scanner)
6. [.user.ini Scanner](#userini-scanner)
7. [Environment Scanner](#environment-scanner)
8. [Baseline Diff Scanner](#baseline-diff-scanner)
9. [Creating and Using a Baseline](#creating-and-using-a-baseline)
10. [Fast Mode vs. Strict Mode](#fast-mode-vs-strict-mode)
11. [Signed Baselines](#signed-baselines)
12. [Running Selective Scans and CI Integration](#running-selective-scans-and-ci-integration)
13. [Installation](#installation)
14. [Key Takeaways](#key-takeaways)

 ###  Have a technical challenge?

 Tell me what you’re building. I reply within two working days.

[Start a conversation](https://www.msaied.com/public#contact) 

   Related articles
-----------------

 [ ![](https://cdn.msaied.com/740/cce86edc21eddcbdd2f2454fadaf9c70.png)  · 3 min read### The Pipeline Pattern in Laravel: Custom Pipelines Beyond Middleware

5 Oct 2026 ](https://www.msaied.com/public/articles/the-pipeline-pattern-in-laravel-custom-pipelines-beyond-middleware-1) [ ![](https://cdn.msaied.com/739/2d6897fdcdcf090613f96f72a64b8a78.png)  · 4 min read### MySQL Full-Text Search in Laravel: Indexes, Relevance Scoring, and Boolean Mode

4 Oct 2026 ](https://www.msaied.com/public/articles/mysql-full-text-search-in-laravel-indexes-relevance-scoring-and-boolean-mode) [ ![](https://cdn.msaied.com/738/073696a3fefe18bec825beec5ac658f5.png)  · 4 min read### Laravel Queue Rate-Limited Middleware: Throttling Jobs Without Losing Work

4 Oct 2026 ](https://www.msaied.com/public/articles/laravel-queue-rate-limited-middleware-throttling-jobs-without-losing-work) 

  Have a technical challenge?
----------------------------

Tell me what you’re building. I reply within two working days.

 [Discuss your project ↗](https://www.msaied.com/public#contact) 

  © 2026 Mohamed Said · Built with Laravel, meant to last.Senior Backend Engineer specializing in Laravel, scalable SaaS platforms, APIs, and cloud infrastructure. I build secure, high-performance web applications that help businesses grow.

 - [Home](https://www.msaied.com/public)
- [Articles](https://www.msaied.com/public/articles)
- [Certificates](https://www.msaied.com/public/certificates)
- [GitHub](https://github.com/EG-Mohamed)
- [LinkedIn](https://www.linkedin.com/in/msaiedm/)
- [WhatsApp](https://wa.me/201094619204)
- [Email Address](mailto:hello@msaied.com)
- [My CV](https://drive.google.com/file/u/0/d/1MF20IPRJyzfy32mhEutjL5EpSls0w2Q8/view)
- [Sitemap](https://www.msaied.com/public/sitemap.xml)
