Anteumbra - Web Perimeter Threat Intelligence. Passive detection, semi-active response, attacker profiling.
Project description
Anteumbra
Lightweight Web Perimeter Security
Passive detection, semi-active response, file-level forensics, and attacker profiling.
中文 | User Manual | Architecture | Roadmap | Release Guide | PyPI | Issues
Anteumbra is a web perimeter threat-intelligence and WebShell detection platform for Windows and Linux. It watches website directories, detects suspicious PHP/ASP/JSP/ASPX files with YARA rules, correlates access logs, profiles attacker behavior, and provides a web dashboard for triage, quarantine, restoration, audit, and reporting.
Anteumbra is installed as one product. PyPI users and source-install developers both create runtime instances with the same anteumbra install and anteumbra config workflow.
Operational Scope
Anteumbra is designed for one host or a small web workload: filesystem integrity monitoring, WebShell detection, local triage and response, and export to an existing security stack. It is not a replacement for an inline WAF, endpoint detection and response, a SIEM, centralized fleet management, or distributed high availability.
Documentation
| Need | English | Chinese |
|---|---|---|
| Install, configure, operate | User Manual | 用户手册 |
| Internal architecture and extension points | Architecture | 架构文档 |
| Current status and planned work | Roadmap | 路线图 |
| Release history | Changelog | 更新日志 |
| Release and PyPI publishing | Release Guide | 发布指南 |
| Memory-shell response references | Toolkit | 工具说明 |
Quick Start
pip install anteumbra
anteumbra install ./anteumbra-instance
cd ./anteumbra-instance
anteumbra config wizard
anteumbra config validate
anteumbra run
pip install places package code in the active Python environment, while
anteumbra install INSTANCE_DIR creates an explicitly located mutable runtime
containing config.toml, .env, data, logs, rules, and quarantine files. They
are two locations for one product. Anteumbra neither creates a virtual
environment nor modifies PATH; install it into the Python environment you
already manage. If the anteumbra console command is not discoverable, use
python -m anteumbra with the same arguments.
Select the runtime explicitly from any working directory:
anteumbra --home /opt/anteumbra config wizard
anteumbra --home /opt/anteumbra start
Windows paths are accepted directly, for example
anteumbra install E:\Software\Anteumbra.
Open http://127.0.0.1:8080/admin. The default username is admin; the initial password is printed by anteumbra install. You can set a new password in anteumbra config wizard.
YARA scanning is included in the base install. Optional similarity engines are
available through the full extra:
pip install anteumbra # includes yara-python
pip install "anteumbra[full]" # adds ssdeep and py-tlsh
anteumbra[yara] remains accepted as a compatibility alias but adds no
dependencies beyond the base package.
Common Configuration
Use the wizard for first-run setup:
anteumbra config wizard
anteumbra config validate
Use preset commands for access-log analysis. This avoids hand-writing platform-specific paths and Tomcat wildcards:
anteumbra config access-log nginx
anteumbra config access-log apache
anteumbra config access-log tomcat --base /opt/tomcat
anteumbra config access-log custom --path /path/to/access.log
anteumbra config access-log none
Low-level scripted edits are still available:
anteumbra config set website.path /var/www/html
anteumbra config set web_admin.port 8080
anteumbra config env set ANTEUMBRA_WECHAT_API_KEY your-send-key
anteumbra config reload
config reload fully parses the selected deployment config but does not
mutate a running service. Apply runtime changes from Web System or restart it.
Running anteumbra config by itself only displays subcommand help and never
creates or overwrites files. Initialization requires anteumbra config init;
only config init --force replaces an existing config.toml and .env
without prompting.
For the full command reference, see CLI Commands.
Core Capabilities
- Multi-site file monitoring on Windows and Linux
- Manual scans with scan history and printable reports
- YARA-based WebShell detection for PHP, ASP, JSP, ASPX, Godzilla, Behinder, and related families
- 27 packaged YARA files compiled independently, so one invalid custom rule file does not disable the remaining rules
- Access-log behavior analysis for Nginx, Apache, and Tomcat
- Attacker profiling, IP reputation, attack chain timelines, and cross-page batch actions
- Quarantine, restore, false-positive marking, and audit trail workflows
- JSON and SQLite storage backends with WAL support
- SIEM export in CEF, JSON Lines, and Syslog formats
- Web dashboard with merged historical/live SSE logs, runtime capability status, and configuration management
- Plugin manager and WAF/event-source integration points
Source Install
Use a source install for development, testing, or local code changes. Runtime setup remains the same as the PyPI flow.
git clone https://github.com/SxyLao1/Anteumbra.git
cd Anteumbra
pip install -e ".[dev]"
anteumbra install ./dev-instance --force
cd ./dev-instance
anteumbra config wizard
anteumbra run
Run tests from the repository root:
python -m pytest
Docker
docker build -t anteumbra .
docker run -d --name anteumbra \
-p 127.0.0.1:18080:8080 \
-v $(pwd)/anteumbra-data:/app/data \
-v $(pwd)/anteumbra-logs:/app/logs \
anteumbra
docker logs anteumbra
The container starts the same full runtime as anteumbra run, creates a
Docker-friendly default config on first start, permits the local Docker gateway
to reach the admin IP allowlist, and prints the initial admin password in
docker logs. Open http://127.0.0.1:18080/admin.
Architecture
Anteumbra follows a layered structure:
src/anteumbra/
domain/ # Entities and ports
application/ # Use cases and orchestration
infrastructure/ # Persistence, detection, monitoring, config, utilities
interfaces/ # CLI, Flask blueprints, templates, static assets
See Architecture for module boundaries, extension guidance, and integration contracts.
Migration From Trident
Anteumbra is the successor to Trident. Existing config.toml and data/ directories are intended to remain compatible; install Anteumbra, create a runtime instance, then copy your existing configuration and data into that instance. See the User Manual before production migration.
License
MIT License. Third-party tools bundled under tools/ retain their original licenses.
Project details
Release history Release notifications | RSS feed
Download files
Download the file for your platform. If you're not sure which to choose, learn more about installing packages.
Source Distribution
Built Distribution
Filter files by name, interpreter, ABI, and platform.
If you're not sure about the file name format, learn more about wheel file names.
Copy a direct link to the current filters
File details
Details for the file anteumbra-1.0.33.tar.gz.
File metadata
- Download URL: anteumbra-1.0.33.tar.gz
- Upload date:
- Size: 428.7 kB
- Tags: Source
- Uploaded using Trusted Publishing? Yes
- Uploaded via: twine/6.1.0 CPython/3.13.14
File hashes
| Algorithm | Hash digest | |
|---|---|---|
| SHA256 |
fd060f74607fe9fec518f020ffddcef7c392a03b07bae81763bbbeb3d73db3d7
|
|
| MD5 |
531b27b37af809271f4a33b61edca107
|
|
| BLAKE2b-256 |
195c95d2934dbb536a0c7152479a2653a2b3c1883d5e9f7e27287e40d4060618
|
Provenance
The following attestation bundles were made for anteumbra-1.0.33.tar.gz:
Publisher:
publish.yml on SxyLao1/Anteumbra
-
Statement:
-
Statement type:
https://in-toto.io/Statement/v1 -
Predicate type:
https://docs.pypi.org/attestations/publish/v1 -
Subject name:
anteumbra-1.0.33.tar.gz -
Subject digest:
fd060f74607fe9fec518f020ffddcef7c392a03b07bae81763bbbeb3d73db3d7 - Sigstore transparency entry: 2206686925
- Sigstore integration time:
-
Permalink:
SxyLao1/Anteumbra@c64054c9d2d31b32887f768557d724580338fc29 -
Branch / Tag:
refs/tags/v1.0.33 - Owner: https://github.com/SxyLao1
-
Access:
public
-
Token Issuer:
https://token.actions.githubusercontent.com -
Runner Environment:
github-hosted -
Publication workflow:
publish.yml@c64054c9d2d31b32887f768557d724580338fc29 -
Trigger Event:
push
-
Statement type:
File details
Details for the file anteumbra-1.0.33-py3-none-any.whl.
File metadata
- Download URL: anteumbra-1.0.33-py3-none-any.whl
- Upload date:
- Size: 530.2 kB
- Tags: Python 3
- Uploaded using Trusted Publishing? Yes
- Uploaded via: twine/6.1.0 CPython/3.13.14
File hashes
| Algorithm | Hash digest | |
|---|---|---|
| SHA256 |
37a595837ad62326eea38052c8a117a6ee2ce2006e6fbac271769fb084d68189
|
|
| MD5 |
f6608bcb8189d0c8b6c4f34a58f41ae2
|
|
| BLAKE2b-256 |
4d0464982d5bfc54c9563140111954acae59ded61e1aee30c93cf19f2378b71b
|
Provenance
The following attestation bundles were made for anteumbra-1.0.33-py3-none-any.whl:
Publisher:
publish.yml on SxyLao1/Anteumbra
-
Statement:
-
Statement type:
https://in-toto.io/Statement/v1 -
Predicate type:
https://docs.pypi.org/attestations/publish/v1 -
Subject name:
anteumbra-1.0.33-py3-none-any.whl -
Subject digest:
37a595837ad62326eea38052c8a117a6ee2ce2006e6fbac271769fb084d68189 - Sigstore transparency entry: 2206686938
- Sigstore integration time:
-
Permalink:
SxyLao1/Anteumbra@c64054c9d2d31b32887f768557d724580338fc29 -
Branch / Tag:
refs/tags/v1.0.33 - Owner: https://github.com/SxyLao1
-
Access:
public
-
Token Issuer:
https://token.actions.githubusercontent.com -
Runner Environment:
github-hosted -
Publication workflow:
publish.yml@c64054c9d2d31b32887f768557d724580338fc29 -
Trigger Event:
push
-
Statement type: