Dev.to Security 🔐 Cybersecurity 👁 0 📖 8 min read

Tripwire Lite: Your Uploads Folder Did Not Hire a PHP Developer

02:13. A file called maintenance.php walks into the uploads directory. It says it is with IT. IT says it has never seen this file before. The file would prefer we stop asking questions and grant it a corner office. T

02:13. A file called maintenance.php walks into the uploads directory.

It says it is with IT.

IT says it has never seen this file before.

The file would prefer we stop asking questions and grant it a corner office.

This is a good job for MatrixSwarm’s Tripwire Lite, the tripwire_lite agent: a filesystem watcher with an extension policy, a dry-run mode, optional quarantine, and a way to call the operator. We will give it a small swarm, connect Phoenix, and watch a harmless test event come back.

The setup is short. The interesting part is teaching the guard what belongs in the building.

First, put MatrixOS on the target

Already installed? Move straight to the workspace.

Otherwise, add and test the Linux server’s SSH connection in Phoenix’s Registry, including its trusted host fingerprint. Open Railgun → Install MatrixOS…, choose the SSH target and an install source: Local Full Install for your local MatrixOS folder, or Install from GitHub. For a fresh installation, choose Create new venv, then Install MatrixOS and wait for successful completion.

Installation needs root or passwordless sudo access on that target. Railgun handles the remote installation; you still check the result. A progress bar moving enthusiastically is not a completion certificate.

Build the little swarm

Use Phoenix’s Deploy button to open Swarm Workspaces. Choose New, or Open an existing workspace to edit it. A new workspace starts with the matrix root. Add these four agents beneath it from the Agent Palette:

Agent Job in this walkthrough
tripwire_lite Watches the selected filesystem paths and applies the policy
matrix_https Ingress: receives Phoenix commands over HTTPS
matrix_websocket Egress: carries live replies and alerts back to Phoenix
log_streamer Supplies the selected agent’s log stream through the reply route

That is five agents including Matrix. A small team. Everybody has a job. Nobody exists solely to forward meeting invitations.

The current palette names the HTTP ingress agent matrix_https. Use that exact name when looking for it.

Resolve the agents’ required Registry assignments before deployment: packet signing, HTTPS/WSS connections and certificates, and Tripwire’s symmetric-encryption key. Configure reachable ingress/egress addresses and ports for your host. Keep the supplied service roles unless you intend to change the routing.

Tripwire can watch locally without a cockpit connection. For this connected walkthrough, include both ingress and egress, plus log_streamer for live agent logs. WebSocket provides the return channel; it does not tail Tripwire’s log file by itself.

Give the guard one door to watch

Begin with a dedicated test directory, such as /srv/tripwire-demo, outside a publicly served web root. Create it on the target and give the swarm’s runtime Linux account the directory access it needs. The path must exist on the server—not on the laptop running Phoenix.

In Tripwire’s configuration editor, replace the broad example watch paths with that directory. Start with directory event watches: watch_dirs: true and watch_files: false. Enable recursive if you want subdirectories covered. Directory watches report events for their entries; direct file watches additionally require file read permission. The underlying mechanism is Linux inotify.

Here is a Tripwire config fragment, not a whole swarm directive. Keep the palette’s service-manager and resolved security configuration around it:

{
  "watch_paths": [
    {
      "path": "/srv/tripwire-demo",
      "recursive": true,
      "watch_dirs": true,
      "watch_files": false
    }
  ],
  "ignore_paths": ["/srv/tripwire-demo/cache"],
  "allowed_extensions": [".txt", ".json", ".jpg", ".png"],
  "suspicious_extensions": [".php", ".phtml", ".sh", ".py", ".exe"],
  "quarantine_root": "",
  "dry_run": true,
  "enforce": true,
  "cooldown": 60,
  "interval": 5,
  "alert_to_role": "hive.alert",
  "rpc_router_role": "hive.rpc"
}

Both mode switches are intentional. Enforce on plus Dry run on rehearses enforcement and can send “would quarantine” alerts while leaving files in place. The palette’s detect-only starting state is a different behavior, so set the values explicitly.

For production, replace the test policy with one that fits the watched location. A PHP file appearing in an image-upload directory deserves attention. A PHP file appearing in your PHP application may simply be reporting for work.

Do not point this sample policy at all your application code—or at MatrixOS’s Python agents—and then act surprised when the guard starts escorting employees outside.

What gets stopped at reception

The current implementation responds to relevant create, modify, and move-in events, then checks the path against its policy:

  • Ignored paths and Tripwire’s own quarantine directory are excluded.
  • An extension in suspicious_extensions is suspicious, even if also listed as allowed.
  • With a nonempty allowed_extensions list, another nonempty extension outside that list is also suspicious.
  • An extensionless name is not rejected merely for being absent from the allowed list.

Use lowercase extensions with their leading dots. A harmless file called visitor.php is enough to exercise the rule; no malicious payload is necessary. This guard checks the badge, not the visitor’s inner monologue.

That last point matters: this is an event-driven extension policy, not a content malware scanner or a hash-baseline integrity system. It does not establish that an allowed .jpg contains a safe image. It does not retroactively classify every existing file at startup, and its enforcement path does not reconstruct deleted files. Keep upload validation, execution restrictions, and backups doing their own jobs.

The editor’s interval setting should not be mistaken for a full-disk malware scan every five seconds. File events arrive through inotify; the regular worker also maintains the agent’s operational heartbeat.

Three shifts, two switches

Enforce Dry run Result for an eligible suspicious event
Off Either Detect-only: logs what would happen; ordinary detection does not dispatch the quarantine alert
On On Logs and can alert “would quarantine”; leaves the file in place
On Off Attempts to move the item into quarantine; can alert the outcome

Alerts are subject to cooldown. In the current implementation, the cooldown uses one timestamp for the agent, so separate paths can share that quiet period. It is not an independent timer for every file.

Cooldown limits notifications, not active quarantine. A quiet phone does not mean the guard has gone on break.

Leave Quarantine Root blank for the agent’s automatic quarantine directory in its universe-specific static storage. The resolved location appears in status/log output, and the guard excludes it from its own watches. Active enforcement needs permission to move items out of the watched directory and into quarantine; merely entering a path in Phoenix grants no filesystem permissions.

Tripwire encrypts its stored quarantine-history records. The quarantined files themselves are moved by the filesystem operation; do not confuse that with encryption of their contents.

Launch it through Railgun

Click Deploy inside the workspace. Give the deployment a label, select the Registry SSH target, choose a universe name and runtime Linux user, review the resolved directive, and complete the launch flow. For a first exercise, use a distinct demo universe. Wait for Railgun’s remote result, then confirm the agents in the cockpit.

Behind the button, Phoenix builds and encrypts the runtime directive and retains the deployment record in its encrypted vault. Railgun verifies the SSH host, prepares the runtime account and applicable grants, and streams the sealed boot envelope to MatrixD over SSH stdin. MatrixD decrypts it in memory and starts the swarm. The directive and swarm key are not left as loose remote boot files.

Installing MatrixOS prepares the host. Deploying launches this swarm. Connect opens the cockpit session; it does not start the swarm. Three jobs, three verbs. We can all go home without inventing a fourth wizard.

Connect, then make the guard earn its chair

Select the new deployment in Phoenix and click Connect. Choose Tripwire in the live agent tree. That selection requests its logs from log_streamer; the replies return through matrix_websocket into Agent Logs. Tripwire’s panel also exposes Refresh Status, Toggle Enforce, Toggle Dry-Run, and Reset Watches.

Check the reported modes, watched paths, watcher setup, and resolved quarantine location. Missing paths, permissions failures, or inotify resource limits need attention before the first test. “Agent exists” and “watch is installed” are different statements.

Now rehearse in that dedicated test directory:

  1. With Enforce on / Dry run on, create a new harmless hello.txt. It is allowed by this sample policy and should not generate a suspicious-file alert.
  2. Create a new visitor.php containing only plain text such as “Tripwire training file.” Look for Would quarantine in the live log and the eligible alert in Phoenix. The file stays put.
  3. If a repeat test is quiet, check the cooldown and live logs before declaring the radio haunted. A simulated event does not create an actual quarantined-file record.
  4. After verifying the policy and move permissions, keep Enforce on and switch Dry run off for a disposable quarantine test. Create another new harmless file with a suspicious extension. Confirm the move in the log and refresh the quarantine list.
  5. Use Restore only for the known-safe test item, then verify the result. Restoring an item does not permanently allow its extension; later events can trigger the policy again. Return to dry-run while tuning.

Quarantine is reactive. It cannot promise that a file was never accessed before being moved. The guard is useful; the guard is not a time machine with a pension plan.

Give it another phone, if you want

The included WebSocket agent advertises hive.alert for Phoenix alerts. Tripwire can also send to reachable Slack, Discord, Telegram, or email relays using that same role, so you can add notifications without replacing the watcher. The relay agents are slack_relay, discord_relay, telegram_relay, and email_send.

Discord, Telegram, and email support optional alert-payload encryption configured on each relay with its assigned keys. That is separate from Tripwire’s encrypted history and from HTTPS/WSS transport. You can keep this first swarm small and add the extra phone numbers once the basic route works.

You have now installed the runtime, built a workspace, launched a swarm, connected the cockpit, and watched a filesystem event turn into an operator-visible result. Repeat that same short deployment habit for the next agent; change the job, keep the routine.

As for maintenance.php: reception would like to see some identification.

Victory Always. Night shift has the door.

🌐 Links & Resources:

Try MatrixSwarm: https://matrixswarm.com

Join the Community / Discord: https://discord.gg/2USbWVBVV

Download Server: https://github.com/matrixswarm/matrixswarm

Youtube: https://www.youtube.com/channel/UCMjiY4_-W2KP5fHXO0eC2ug

📰 Read the original article on Dev.to Security

Originally published by Dev.to Security. Aggregated on AIWithGhost for educational purposes — full credit and traffic to the original publisher.