--- name: vulnerability-analysis description: Use when auditing source code for vulnerabilities — drive CodeQL/Semgrep/Joern to taint untrusted data source-to-sink across injection, memory safety, deserialization/prototype-pollution, secrets/crypto/authz/race, and supply-chain risks metadata: type: offensive phase: analysis tools: codeql, semgrep, joern, opengrep, trufflehog, gitleaks, kingfisher, osv-scanner, syft, grype, trivy, npm-audit, pip-audit, ysoserial, phpggc mitre: [T1190, T1059, T1552.001, T1195.001, T1213] kill_chain: phase: [recon, exploit] step: [1, 4] attck_tactics: [TA0043, TA0002, TA0001] attck_techniques: [T1190, T1059, T1552.001, T1195.001, T1195.002] depends_on: [recon-osint] feeds_into: [exploit-development, web-pentest] inputs: [attack_surface_map, source_code] outputs: [vulnerability_list, taint_analysis_report, finding_record, sbom] references: - references/taint-engines-static-analysis.md - references/injection-source-patterns.md - references/memory-safety-c-cpp.md - references/deserialization-prototype-pollution.md - references/secrets-crypto-authz-concurrency.md - references/supply-chain-dependency-audit.md - references/variant-hunting.md scripts: - scripts/taint_trace.py - scripts/sast_runner.py - scripts/joern_taint.sc - scripts/deser_gadget_scan.py - scripts/secret_crypto_audit.py - scripts/dep_audit.py - scripts/validate_findings.py - scripts/evidence_kit.py - scripts/variant_hunt.py - scripts/path_conditions.py - scripts/merge_runtime_evidence.py --- # Vulnerability Analysis Every vulnerability you miss is one an attacker finds first. Systematic source auditing traces untrusted data from **source** to **sink**, evaluates every sanitizer for bypass, and questions each trust-boundary assumption. This skill is the router; depth lives in `references/`, and every technique cluster is backed by a runnable tool in `scripts/`. ## When to Activate - Auditing any codebase (white/grey box) for security vulnerabilities - Writing/driving CodeQL queries, Semgrep taint rules, or Joern CPGQL flows - Tracing injection, deserialization, prototype-pollution, or memory-safety paths - Reviewing auth/authorization (IDOR/BOLA), cryptography, or concurrency (TOCTOU) - Triaging dependency CVEs and hunting malicious/compromised packages (SCA) - Variant hunting — generalizing one finding into a codebase-wide pattern ## Technique Map | Technique | ATT&CK | CWE | Reference | Script | |-----------|--------|-----|-----------|--------| | Taint analysis (source/sink/sanitizer modeling) | T1190 | CWE-20 | references/taint-engines-static-analysis.md | scripts/taint_trace.py | | CodeQL/Semgrep/Joern engine orchestration + merge | T1190 | CWE-20 | references/taint-engines-static-analysis.md | scripts/sast_runner.py, scripts/joern_taint.sc | | SQL injection (raw/ORM/identifier/2nd-order/NoSQL) | T1190 | CWE-89 | references/injection-source-patterns.md | scripts/taint_trace.py | | OS command / argument injection | T1059 | CWE-78 / CWE-88 | references/injection-source-patterns.md | scripts/taint_trace.py | | Server-side template injection | T1190 | CWE-1336 | references/injection-source-patterns.md | scripts/taint_trace.py | | Path traversal | T1083 | CWE-22 | references/injection-source-patterns.md | scripts/taint_trace.py | | SSRF (tainted server-side URL) | T1190 | CWE-918 | references/injection-source-patterns.md | scripts/taint_trace.py | | Integer overflow -> heap/stack overflow | T1203 | CWE-190 / CWE-787 | references/memory-safety-c-cpp.md | scripts/joern_taint.sc | | Use-after-free / double-free | T1203 | CWE-416 / CWE-415 | references/memory-safety-c-cpp.md | scripts/joern_taint.sc | | Unbounded copy / NULL deref | T1203 | CWE-120 / CWE-476 | references/memory-safety-c-cpp.md | scripts/joern_taint.sc | | Insecure deserialization + gadget preconditions | T1059 | CWE-502 | references/deserialization-prototype-pollution.md | scripts/deser_gadget_scan.py | | Prototype pollution -> gadget -> RCE | T1059.007 | CWE-1321 | references/deserialization-prototype-pollution.md | scripts/deser_gadget_scan.py | | Hardcoded secrets / high-entropy literals | T1552.001 | CWE-798 / CWE-321 | references/secrets-crypto-authz-concurrency.md | scripts/secret_crypto_audit.py | | Weak / misused cryptography | T1600 | CWE-327 / CWE-328 / CWE-330 / CWE-347 | references/secrets-crypto-authz-concurrency.md | scripts/secret_crypto_audit.py | | Broken authorization / IDOR / BOLA | T1190 | CWE-639 / CWE-862 | references/secrets-crypto-authz-concurrency.md | scripts/secret_crypto_audit.py | | TOCTOU / race condition | T1190 | CWE-367 / CWE-362 | references/secrets-crypto-authz-concurrency.md | scripts/secret_crypto_audit.py | | Known-CVE dependency (SCA) | T1195.001 | CWE-1395 / CWE-1104 | references/supply-chain-dependency-audit.md | scripts/dep_audit.py | | Malicious package / install worm / typosquat | T1195.002 | CWE-506 / CWE-829 / CWE-1357 | references/supply-chain-dependency-audit.md | scripts/dep_audit.py | | Variant hunting — one finding -> all siblings, root-cause clustered | T1190 | CWE-20 | references/variant-hunting.md | scripts/variant_hunt.py | | Path feasibility — branch guards -> tri-state SAT/UNSAT (Z3 optional) | T1190 | CWE-20 | references/taint-engines-static-analysis.md | scripts/path_conditions.py | | Evidence grounding + FP gate (structured proof, EVD citations) | T1190 | CWE-20 | references/finding-validation-runtime.md | scripts/validate_findings.py, scripts/evidence_kit.py | | Runtime reachability confirmation (Frida sink-executed) | T1190 | CWE-20 | references/dynamic-instrumentation.md | scripts/merge_runtime_evidence.py | ## Quick Start ```bash # 0. Intake from recon-osint: languages, frameworks, trust boundaries, entry points. # 1. Fast triage — rank files by unsanitized source->sink flows (heuristic, multi-lang) python3 scripts/taint_trace.py trace ./src --lang py,js,php,java --json triage.json python3 scripts/taint_trace.py config --lang py > seed.semgrep.yml # seed a real rule # 2. Deep interprocedural — drive the real engines, then merge into one ranked list python3 scripts/sast_runner.py semgrep --src ./src --config p/owasp-top-ten --pro --out sg.sarif python3 scripts/sast_runner.py codeql --src ./src --lang python \ --suite codeql/python-queries:codeql-suites/python-security-extended.qls --out cq.sarif python3 scripts/sast_runner.py joern --src ./src --script scripts/joern_taint.sc --out joern.json python3 scripts/sast_runner.py merge sg.sarif cq.sarif joern.json --out merged.json --top 50 # 3. Class-specific deep passes python3 scripts/deser_gadget_scan.py all ./src --json deser.json # deser sinks + gadget libs python3 scripts/secret_crypto_audit.py all ./src --json sca.json # secrets+crypto+authz+TOCTOU python3 scripts/dep_audit.py all ./repo --json dep.json # CVE SCA + worm/typosquat trufflehog filesystem ./src --only-verified # confirm LIVE secrets # 4. Exploitability gate (per finding): reachable? controllable? real impact? sanitizer real? # -> write confirmed issues to templates/exploit/findings/ with # severity, CWE, CVSS, taint path, PoC, evidence, ATT&CK ID, remediation. python3 scripts/evidence_kit.py verify --store evidence.json # re-hash every artifact python3 scripts/validate_findings.py --findings findings.json \ --evidence ./evidence --evidence-store evidence.json --strict # tier + EVD-citation gate # 5. After a CONFIRMED finding: hunt every sibling, then prune false-positive paths python3 scripts/variant_hunt.py ./src --seed-finding findings.json --lang py,js --json variants.json python3 scripts/taint_trace.py trace ./src --lang py --json trace.json # trace carries branch guards python3 scripts/path_conditions.py --trace trace.json --json feasibility.json # Z3 prune (tri-state) python3 scripts/merge_runtime_evidence.py --events events.jsonl --findings findings.json --out merged.json ``` ## OPSEC & Detection (summary) | Technique | Telemetry / IOC | Detection (Sigma/EDR) | OPSEC note | |-----------|-----------------|------------------------|------------| | SAST engine runs | `codeql database create`, `semgrep --sarif`, `joern-parse` process trees; large `codeql-db/`/`cpg.bin` | CI process-creation Sigma (informational) | offline & silent; CodeQL `--command` runs target build -> sandbox hostile repos; purge DBs/SARIF on teardown | | Injection (SQLi/cmdi/SSTI/SSRF) | SQL keywords/`SLEEP`, web svc spawning `sh/curl`, template engine errors, OOB DNS | webserver regex + EDR child-shell Sigma | source review is noiseless; validate with time-based/DNS-OOB, never `--dump` | | Memory safety (C/C++) | SIGSEGV/SIGABRT, glibc `corrupted`/`double free`, ASan reports | auditd ANOM_ABEND Sigma; EDR RWX/W^X alerts | CPG review silent; fuzz a local copy in a container, purge cores (may hold secrets) | | Deserialization / proto-pollution | Java `rO0AB`/.NET `AAEAAAD/////` in bodies; JVM->LDAP/RMI; `POST /` w/ `Next-Action` (CVE-2025-55182) | egress Sigma to 389/636/1099/1389; body-marker rules | prove gadget chain exists; `id`/DNS callback not reverse shell; proto-pollution is global -> revert | | Secrets / crypto / authz / TOCTOU | `AKIA*`/`ghp_*` patterns; `alg:none`; sequential-id 200s; symlink-race auditd | secret-scanning push protection; symlink/PATH auditd | secret *verification* makes a logged provider API call -> only in scope; read one record for IDOR/TOCTOU evidence | | Supply chain (SCA / worm) | install hook spawning shell/net; `bundle.js`/`setup_bun.js`; new public `Shai-Hulud` repo | install-script process-creation Sigma; agentless SBOM lookup | never `npm install` a suspect tree; `--ignore-scripts` in a disposable container; treat a compromised dep as full host compromise | ## Deep Dives - references/taint-engines-static-analysis.md — taint theory + propagation rules; Semgrep (taint mode, Pro interfile, Opengrep), CodeQL modular dataflow API, Joern CPG/`reachableBy`; engine orchestration + multi-tool merge; CPG+LLM (2025). - references/injection-source-patterns.md — source-code shapes of SQLi (incl. identifier/ORDER BY/2nd-order/NoSQL), OS command & argument injection, SSTI, path traversal, SSRF; per-language safe/vuln pairs; Joern/Semgrep confirmation. - references/memory-safety-c-cpp.md — integer overflow->overflow, UAF/double-free, unbounded copy, NULL deref; the 2025 libxml2 CVE cluster; ASan/UBSan + fuzzing confirmation; `unsafe` Rust surface. - references/deserialization-prototype-pollution.md — CWE-502 sinks + gadget preconditions (ysoserial/phpggc/ysoserial.net), JS prototype pollution->RCE; React2Shell CVE-2025-55182, Tomcat CVE-2025-24813, lodash CVE-2025-13465, Silent Spring. - references/secrets-crypto-authz-concurrency.md — hardcoded secrets (gitleaks/ trufflehog/Kingfisher), weak crypto, IDOR/BOLA, TOCTOU/race; LLM-augmented secret detection (2025). - references/supply-chain-dependency-audit.md — OSV/SCA, malicious-package & install worm heuristics, typosquats; Shai-Hulud 1.0/2.0/Mini (CVE-2026-45321), the SLSA provenance-bypass lesson. - references/variant-hunting.md — HUNT protocol: one confirmed finding -> tree-wide sibling sweep, same-function taint qualification, root-cause clustering (copy-paste/shared-util/ framework-misuse) to decide one-fix-or-many; backed by `variant_hunt.py`. Pairs with `evidence_kit.py` (re-verifiable EVD evidence), `path_conditions.py` (Z3 path-prune, tri-state), and `merge_runtime_evidence.py` (Frida runtime sink confirmation).