IN PROGRESS
Technical summary
IAST plugin that observes real requests in PHP applications and detects when user input reaches SQL, command, file, deserialization or redirect sinks. Its standalone agent runs in basic mode or with uopz hooks, sends authenticated findings to NEXUS, and provides deduplication, heartbeat, self-test and automatic task creation with per-project routing.
Executed scope
- Standalone runtime agent
agent/nexus-iast.php(417 lines):boot(config + optionalconfig_file),captureSources,isTainted/matchingSource,report(withsample_rate,max_findings, stack trace viadebug_backtrace), per-vuln-type checks with heuristics,tryUopzHooks(hooks onshell_exec/exec/system/passthru/file_get_contents/fopen/unserialize),flushat shutdown (curl orfile_get_contentsstream,X-IAST-Tokenheader),NexusIast::exec/readFile(helpers without uopz) andNexusIastPDO extends PDO(instrumented query/exec/prepare). - Schema (
iast_install()on load, no install.sql):iast_findings(id PK, agent_id, project, vuln_type, severity, file_path, line_number, function_name, user_input, sink_function, stack_trace MEDIUMTEXT, request_url, request_method, evidence, fingerprint, status, task_id, indexes per agent/type/sev/status/fp/created) +iast_agents(agent_id PK, label, project, last_seen_at, findings_count, meta JSON) + light migration of thesourcecolumn (runtime/self_test/manual). - 13 API actions via
PluginManager::registerApiAction—iast_stats,iast_settings,iast_settings_save,iast_findings(page/limit + severity/status/vuln_type/agent_id/q filters),iast_finding_status(open/resolved/ignored),iast_agents,iast_ingest(public with token, batch ≤ 100),iast_self_test,iast_purge_demo,iast_capabilities,iast_fastr,iast_fastr_suggest,iast_agent_snippet(snippet tuned to the host's recommended mode). - Environment detection
iast_env_capabilities(): profile from signals (open_basedir, disabled sensitive functions, uopz, max_execution_time) →shared_hosting/vps_full/vps_or_shared_basic, recommended mode (fullif uopz, otherwisebasic), with guidance limits; works on shared and VPS (requires_vps: false). - Multi-project:
iast_resolve_task_project()withdefault(always the default project),from_agent(uses the agent'sprojectif it exists in NEXUS) andmap(agent→project routes, up to 50, validated against active projects viaprojects_read()). - Task creation:
iast_create_task_for_finding()— title[IAST][SEV] TYPE via SINK, markdown description with input/evidence, resolved project, severity-based priority (critical 4 → low 1), pending status; triggered whenauto_create_tasksand severity ≥min_severity_for_task. - Ingestion:
iast_validate_ingest_token(X-IAST-Tokenheader or body,hash_equals; without a configured token accepts master/session),iast_fingerprint, dedupe by window (dedupe_hours1–168), heartbeat upsert iniast_agents. /iastcommand viafastr.json(arg_suggest_action: iast_fastr_suggest):stats,findings,open,env,selftestwith readable markdown replies.- Alpine.js UI
tab.php(25 KB): sub-tabs Findings (filters + self-test + demo purge), Agents (heartbeat), Install (snippet with endpoint/token/recommended mode) and Config (token with rotate, auto_create_tasks, min_severity, dedupe_hours, project_mode and routes). - Core whitelist:
iast_ingestin the auth bypass ofapi.php(line ~58, alongsideincoming_webhook/github_callback).
Stack and tooling
- PHP 8 (no framework) — standalone agent compatible with any PHP app
- MySQL 8 (
iast_findings,iast_agents) - cURL (agent telemetry) + stream fallback (
allow_url_fopen) - uopz (
uopz_set_return— full mode, optional) - Alpine.js + Tailwind CSS
- NEXUS plugin system (
PluginManager+ auth whitelist inapi.php)
Operational tags
- IAST
- Runtime
- PHP
- DevSecOps
- SQLi
- CMDi
- Security Agent
- Plugin NEXUS
Operational outcome
- Real runtime coverage: findings generated from actual requests (not static analysis), with stack trace, URL, method and tainted input — complementing NEXUS SAST/DAST.
- Works on any host: basic mode on shared/VPS without root/SSH, and full mode on VPS with uopz for automatic native hooks without changing app code.
- Zero app impact: findings sent at shutdown (async curl, 800 ms timeout), configurable
sample_rateandmax_findingsfor CPU-limited hosts. - Fingerprint dedupe + agent heartbeats keep the dashboard accurate and noise-free; self-test validates the pipeline without producing false positives in production (one-click demo purge).
- Task integration: high-severity findings become tasks automatically in the right project (default/from_agent/map), with severity-based priority.
/iastin chat: stats, findings, environment and self-test straight from the comment editor.
GitHub progress (issues)
Real-time panel with latest repository issues.
live feed
open issues on GitHubcarregando andamento...
não foi possivel carregar as issues agora. abra no github pelo link acima.
Real results
NEXUS PHP runtime IAST (DevSecOps) that observes real requests inside the target app and reports user input reaching dangerous sinks — basic mode (shared/VPS, no root) and full mode (VPS + uopz) — with automatic multi-project task creation.
Architecture and organization
- PHP 8
- MySQL 8
- Alpine.js
- Tailwind CSS
- uopz
- cURL
- Plugin NEXUS
Execution and operations
The project follows reproducible execution flow with technical validation in production-like environments.
Screenshots
Talk about this project
Apply this implementation pattern in your environment and accelerate delivery with technical consistency.