# 00-default.rules: probes no real visitor sends, anchored at the site root # id target action regex env-file path ban (?i)^/\.env(\.[a-z]+)?$ vcs-dir path ban (?i)^/\.(git|svn|hg|bzr)(/|$) secrets-dir path ban (?i)^/\.(aws|ssh|docker|kube)/ secret-file path ban (?i)^/\.(htpasswd|htaccess|npmrc|netrc|pgpass|git-credentials|bash_history|DS_Store)$ editor-dir path ban (?i)^/\.(vscode|idea)/ backup-file path ban (?i)^/[^/]+\.(php(\.[a-z0-9]+|~)|sql(\.[a-z0-9]+)?)$ log-file path ban (?i)^/(debug|error|access)\.log$ compose-file path ban (?i)^/(docker-)?compose\.ya?ml$ php-shell path ban (?i)^/(shell|c99|r57|wso|alfa)\.php$ scanner-agent user_agent ban (?i)\b(sqlmap|nikto|nuclei|masscan|zgrab|wpscan)\b path-traversal uri block (\.\./){2,} empty-agent user_agent log ^$