SHELLHUNTCobraSEC
ZERO-TRUST · CLIENT-SIDE
Webshell & backdoor triage

Hunt shells.
Keep the code.

Drop a webroot, folder, or .zip. Detection runs entirely in your browser — files are never uploaded. We literally cannot see your source.

NO UPLOADFileReader + local JS only
NO ACCOUNTStateless · no storage
EVIDENCESnippet · severity · hash

Drop files / folder / .zip

PHP · ASP · JSP · htaccess · scripts — scanned offline in this tab

Loading…