Security: Delta-Sec/FalconDefender

Security

SECURITY.md

🛡️ FalconDefender Security Policy

The FalconDefender team and the Delta-Security community take the security of this framework very seriously. We appreciate your efforts to responsibly disclose any vulnerabilities you may find.

📈 Supported Versions

Security is a rapidly evolving field, and to ensure the safety of our users, we are only able to provide security support and patches for the most recent stable version of FalconDefender.

VersionSupported
main 2.0.0 (latest)
< 1.5.0

If you are not using the latest version, please upgrade before reporting a vulnerability to ensure it has not already been fixed.


✉️ How to Report a Vulnerability

PLEASE DO NOT DISCLOSE VULNERABILITIES PUBLICLY.

Do NOT open a public GitHub Issue for a security vulnerability. This can put other users of the tool at risk.

Instead, we ask that you report all security issues privately by emailing our security contact:

Please use a clear and descriptive subject line, such as "Security Vulnerability in Falcon Daemon" or "Privilege Escalation in Quarantine Manager".


📝 What to Include in Your Report

To help us validate and fix the vulnerability as quickly as possible, please include the following in your report:

  1. A Clear Description: A brief summary of the vulnerability and its potential impact.
  2. Affected Component: Specify which part of the framework is affected:
    • The Daemon Service (e.g., falcon_daemon.py, scheduler.py, updater.py)
    • The Core Scanner (e.g., scanner.py, yara_manager.py)
    • The User Interfaces (e.g., app.py (TUI), cli.py)
    • The Quarantine Vault (e.g., quarantine.py, quarantine.db)
  3. Steps to Reproduce (PoC): A clear, step-by-step guide on how an attacker could exploit the vulnerability.
  4. Environment: Your operating system, Python version, and YARA version.
  5. (Optional) Suggested Fix: If you have an idea of how to fix the issue, please let us know.

⏳ Our Commitment (What to Expect)

When you report a vulnerability to us, you can expect the following:

  1. We will respond to your report promptly, typically within 48 hours, to acknowledge we have received it.
  2. We will conduct an internal investigation to confirm the vulnerability.
  3. We will work on a patch and prepare a new release.
  4. We will keep you updated on our progress and notify you once the vulnerability is patched.
  5. We will happily give you public credit (if you wish) in the release notes for your contribution to the security of the FalconDefender community.

There aren't any published security advisories

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Add copy buttons to all
 blocks\n(function() {\n function addCopyButtons() {\n document.querySelectorAll('pre code').forEach(function(codeBlock) {\n if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;\n codeBlock.parentElement.setAttribute('data-copy-added', 'true');\n \n var btn = document.createElement('button');\n btn.textContent = 'Copy';\n btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';\n btn.onmouseover = function() { this.style.opacity = '1'; };\n btn.onmouseout = function() { this.style.opacity = '0.7'; };\n btn.onclick = function() {\n navigator.clipboard.writeText(codeBlock.textContent).then(function() {\n btn.textContent = 'Copied!';\n setTimeout(function() { btn.textContent = 'Copy'; }, 1500);\n });\n };\n codeBlock.parentElement.style.position = 'relative';\n codeBlock.parentElement.appendChild(btn);\n });\n }\n \n addCopyButtons();\n \n // Re-run on dynamic content\n var observer = new MutationObserver(addCopyButtons);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Add Copy Buttons to Code Blocks");
}
} catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
})();
(function(){
try {
var __m = "github.com";
var __re = new RegExp('^' + "github\\.com" + '
Skip to content

Security: Delta-Sec/FalconDefender

Security

SECURITY.md

🛡️ FalconDefender Security Policy

The FalconDefender team and the Delta-Security community take the security of this framework very seriously. We appreciate your efforts to responsibly disclose any vulnerabilities you may find.

📈 Supported Versions

Security is a rapidly evolving field, and to ensure the safety of our users, we are only able to provide security support and patches for the most recent stable version of FalconDefender.

VersionSupported
main 2.0.0 (latest)
< 1.5.0

If you are not using the latest version, please upgrade before reporting a vulnerability to ensure it has not already been fixed.


✉️ How to Report a Vulnerability

PLEASE DO NOT DISCLOSE VULNERABILITIES PUBLICLY.

Do NOT open a public GitHub Issue for a security vulnerability. This can put other users of the tool at risk.

Instead, we ask that you report all security issues privately by emailing our security contact:

Please use a clear and descriptive subject line, such as "Security Vulnerability in Falcon Daemon" or "Privilege Escalation in Quarantine Manager".


📝 What to Include in Your Report

To help us validate and fix the vulnerability as quickly as possible, please include the following in your report:

  1. A Clear Description: A brief summary of the vulnerability and its potential impact.
  2. Affected Component: Specify which part of the framework is affected:
    • The Daemon Service (e.g., falcon_daemon.py, scheduler.py, updater.py)
    • The Core Scanner (e.g., scanner.py, yara_manager.py)
    • The User Interfaces (e.g., app.py (TUI), cli.py)
    • The Quarantine Vault (e.g., quarantine.py, quarantine.db)
  3. Steps to Reproduce (PoC): A clear, step-by-step guide on how an attacker could exploit the vulnerability.
  4. Environment: Your operating system, Python version, and YARA version.
  5. (Optional) Suggested Fix: If you have an idea of how to fix the issue, please let us know.

⏳ Our Commitment (What to Expect)

When you report a vulnerability to us, you can expect the following:

  1. We will respond to your report promptly, typically within 48 hours, to acknowledge we have received it.
  2. We will conduct an internal investigation to confirm the vulnerability.
  3. We will work on a patch and prepare a new release.
  4. We will keep you updated on our progress and notify you once the vulnerability is patched.
  5. We will happily give you public credit (if you wish) in the release notes for your contribution to the security of the FalconDefender community.

There aren't any published security advisories

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Force GitHub README to respect dark mode\n(function() {\n var style = document.createElement('style');\n style.textContent = '\n .markdown-body {\n color-scheme: dark light;\n }\n .markdown-body pre { background: #161b22 !important; }\n .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; }\n .markdown-body table th, .markdown-body table td { border-color: #30363d !important; }\n .markdown-body img { background: #0d1117; }\n .markdown-body blockquote { border-left-color: #8b949e; }\n .markdown-body hr { border-color: #30363d; }\n ';\n document.head.appendChild(style);\n})();", "GitHub Dark Mode README Fix"); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Security: Delta-Sec/FalconDefender

Security

SECURITY.md

🛡️ FalconDefender Security Policy

The FalconDefender team and the Delta-Security community take the security of this framework very seriously. We appreciate your efforts to responsibly disclose any vulnerabilities you may find.

📈 Supported Versions

Security is a rapidly evolving field, and to ensure the safety of our users, we are only able to provide security support and patches for the most recent stable version of FalconDefender.

VersionSupported
main 2.0.0 (latest)
< 1.5.0

If you are not using the latest version, please upgrade before reporting a vulnerability to ensure it has not already been fixed.


✉️ How to Report a Vulnerability

PLEASE DO NOT DISCLOSE VULNERABILITIES PUBLICLY.

Do NOT open a public GitHub Issue for a security vulnerability. This can put other users of the tool at risk.

Instead, we ask that you report all security issues privately by emailing our security contact:

Please use a clear and descriptive subject line, such as "Security Vulnerability in Falcon Daemon" or "Privilege Escalation in Quarantine Manager".


📝 What to Include in Your Report

To help us validate and fix the vulnerability as quickly as possible, please include the following in your report:

  1. A Clear Description: A brief summary of the vulnerability and its potential impact.
  2. Affected Component: Specify which part of the framework is affected:
    • The Daemon Service (e.g., falcon_daemon.py, scheduler.py, updater.py)
    • The Core Scanner (e.g., scanner.py, yara_manager.py)
    • The User Interfaces (e.g., app.py (TUI), cli.py)
    • The Quarantine Vault (e.g., quarantine.py, quarantine.db)
  3. Steps to Reproduce (PoC): A clear, step-by-step guide on how an attacker could exploit the vulnerability.
  4. Environment: Your operating system, Python version, and YARA version.
  5. (Optional) Suggested Fix: If you have an idea of how to fix the issue, please let us know.

⏳ Our Commitment (What to Expect)

When you report a vulnerability to us, you can expect the following:

  1. We will respond to your report promptly, typically within 48 hours, to acknowledge we have received it.
  2. We will conduct an internal investigation to confirm the vulnerability.
  3. We will work on a patch and prepare a new release.
  4. We will keep you updated on our progress and notify you once the vulnerability is patched.
  5. We will happily give you public credit (if you wish) in the release notes for your contribution to the security of the FalconDefender community.

There aren't any published security advisories

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Highlight search terms from Google/DuckDuckGo/Bing referrer\n(function() {\n var ref = document.referrer;\n var terms = [];\n \n if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) {\n var url = new URL(ref);\n var q = url.searchParams.get('q') || url.searchParams.get('p');\n if (q) {\n terms = q.split(/\\s+/).filter(function(t) { return t.length > 2; });\n }\n }\n \n if (terms.length === 0) return;\n \n var style = document.createElement('style');\n style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }';\n document.head.appendChild(style);\n \n function highlight(node) {\n if (node.nodeType === 3) { // text node\n var text = node.textContent;\n var found = false;\n terms.forEach(function(term) {\n var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\\]\\\\]/g, '\\\\') + ')', 'gi');\n if (regex.test(text)) {\n found = true;\n var frag = document.createDocumentFragment();\n var parts = text.split(regex);\n parts.forEach(function(part, i) {\n if (i % 2 === 0) {\n frag.appendChild(document.createTextNode(part));\n } else {\n var span = document.createElement('span');\n span.className = 'userscript-highlight';\n span.textContent = part;\n frag.appendChild(span);\n }\n });\n node.parentNode.replaceChild(frag, node);\n }\n });\n } else if (node.nodeType === 1 && node.childNodes) { // element\n var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT'];\n if (!skipTags.includes(node.tagName)) {\n Array.from(node.childNodes).forEach(highlight);\n }\n }\n }\n \n highlight(document.body);\n \n // Re-highlight on dynamic content\n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1 || node.nodeType === 3) highlight(node);\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Highlight Search Terms"); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Security: Delta-Sec/FalconDefender

Security

SECURITY.md

🛡️ FalconDefender Security Policy

The FalconDefender team and the Delta-Security community take the security of this framework very seriously. We appreciate your efforts to responsibly disclose any vulnerabilities you may find.

📈 Supported Versions

Security is a rapidly evolving field, and to ensure the safety of our users, we are only able to provide security support and patches for the most recent stable version of FalconDefender.

VersionSupported
main 2.0.0 (latest)
< 1.5.0

If you are not using the latest version, please upgrade before reporting a vulnerability to ensure it has not already been fixed.


✉️ How to Report a Vulnerability

PLEASE DO NOT DISCLOSE VULNERABILITIES PUBLICLY.

Do NOT open a public GitHub Issue for a security vulnerability. This can put other users of the tool at risk.

Instead, we ask that you report all security issues privately by emailing our security contact:

Please use a clear and descriptive subject line, such as "Security Vulnerability in Falcon Daemon" or "Privilege Escalation in Quarantine Manager".


📝 What to Include in Your Report

To help us validate and fix the vulnerability as quickly as possible, please include the following in your report:

  1. A Clear Description: A brief summary of the vulnerability and its potential impact.
  2. Affected Component: Specify which part of the framework is affected:
    • The Daemon Service (e.g., falcon_daemon.py, scheduler.py, updater.py)
    • The Core Scanner (e.g., scanner.py, yara_manager.py)
    • The User Interfaces (e.g., app.py (TUI), cli.py)
    • The Quarantine Vault (e.g., quarantine.py, quarantine.db)
  3. Steps to Reproduce (PoC): A clear, step-by-step guide on how an attacker could exploit the vulnerability.
  4. Environment: Your operating system, Python version, and YARA version.
  5. (Optional) Suggested Fix: If you have an idea of how to fix the issue, please let us know.

⏳ Our Commitment (What to Expect)

When you report a vulnerability to us, you can expect the following:

  1. We will respond to your report promptly, typically within 48 hours, to acknowledge we have received it.
  2. We will conduct an internal investigation to confirm the vulnerability.
  3. We will work on a patch and prepare a new release.
  4. We will keep you updated on our progress and notify you once the vulnerability is patched.
  5. We will happily give you public credit (if you wish) in the release notes for your contribution to the security of the FalconDefender community.

There aren't any published security advisories

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Strip utm_, fbclid, gclid, etc. from all links on page\n(function() {\n var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content',\n 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid',\n 'ref', 'ref_src', 'source', 'medium', 'campaign'];\n \n function cleanUrl(url) {\n try {\n var u = new URL(url, window.location.origin);\n var changed = false;\n trackingParams.forEach(function(p) {\n if (u.searchParams.has(p)) {\n u.searchParams.delete(p);\n changed = true;\n }\n });\n return changed ? u.toString() : url;\n } catch (e) {\n return url;\n }\n }\n \n function cleanLinks() {\n document.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n \n cleanLinks();\n \n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1) {\n if (node.tagName === 'A') cleanLinks();\n node.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Remove Tracking Parameters from Links"); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + '
Skip to content

Security: Delta-Sec/FalconDefender

Security

SECURITY.md

🛡️ FalconDefender Security Policy

The FalconDefender team and the Delta-Security community take the security of this framework very seriously. We appreciate your efforts to responsibly disclose any vulnerabilities you may find.

📈 Supported Versions

Security is a rapidly evolving field, and to ensure the safety of our users, we are only able to provide security support and patches for the most recent stable version of FalconDefender.

VersionSupported
main 2.0.0 (latest)
< 1.5.0

If you are not using the latest version, please upgrade before reporting a vulnerability to ensure it has not already been fixed.


✉️ How to Report a Vulnerability

PLEASE DO NOT DISCLOSE VULNERABILITIES PUBLICLY.

Do NOT open a public GitHub Issue for a security vulnerability. This can put other users of the tool at risk.

Instead, we ask that you report all security issues privately by emailing our security contact:

Please use a clear and descriptive subject line, such as "Security Vulnerability in Falcon Daemon" or "Privilege Escalation in Quarantine Manager".


📝 What to Include in Your Report

To help us validate and fix the vulnerability as quickly as possible, please include the following in your report:

  1. A Clear Description: A brief summary of the vulnerability and its potential impact.
  2. Affected Component: Specify which part of the framework is affected:
    • The Daemon Service (e.g., falcon_daemon.py, scheduler.py, updater.py)
    • The Core Scanner (e.g., scanner.py, yara_manager.py)
    • The User Interfaces (e.g., app.py (TUI), cli.py)
    • The Quarantine Vault (e.g., quarantine.py, quarantine.db)
  3. Steps to Reproduce (PoC): A clear, step-by-step guide on how an attacker could exploit the vulnerability.
  4. Environment: Your operating system, Python version, and YARA version.
  5. (Optional) Suggested Fix: If you have an idea of how to fix the issue, please let us know.

⏳ Our Commitment (What to Expect)

When you report a vulnerability to us, you can expect the following:

  1. We will respond to your report promptly, typically within 48 hours, to acknowledge we have received it.
  2. We will conduct an internal investigation to confirm the vulnerability.
  3. We will work on a patch and prepare a new release.
  4. We will keep you updated on our progress and notify you once the vulnerability is patched.
  5. We will happily give you public credit (if you wish) in the release notes for your contribution to the security of the FalconDefender community.

There aren't any published security advisories

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Auto-enable theater mode on YouTube\n(function() {\n function tryTheater() {\n var btn = document.querySelector('button[aria-label=\"Theater mode\"], ytd-player #player button[title=\"Theater mode\"]');\n if (btn && !btn.classList.contains('activated')) {\n btn.click();\n }\n }\n \n // Try immediately\n tryTheater();\n \n // Try after navigation (SPA)\n var lastUrl = location.href;\n setInterval(function() {\n if (location.href !== lastUrl) {\n lastUrl = location.href;\n setTimeout(tryTheater, 500);\n }\n }, 1000);\n \n // Also try on player load\n var observer = new MutationObserver(tryTheater);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "YouTube Theater Mode Default"); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Security: Delta-Sec/FalconDefender

Security

SECURITY.md

🛡️ FalconDefender Security Policy

The FalconDefender team and the Delta-Security community take the security of this framework very seriously. We appreciate your efforts to responsibly disclose any vulnerabilities you may find.

📈 Supported Versions

Security is a rapidly evolving field, and to ensure the safety of our users, we are only able to provide security support and patches for the most recent stable version of FalconDefender.

VersionSupported
main 2.0.0 (latest)
< 1.5.0

If you are not using the latest version, please upgrade before reporting a vulnerability to ensure it has not already been fixed.


✉️ How to Report a Vulnerability

PLEASE DO NOT DISCLOSE VULNERABILITIES PUBLICLY.

Do NOT open a public GitHub Issue for a security vulnerability. This can put other users of the tool at risk.

Instead, we ask that you report all security issues privately by emailing our security contact:

Please use a clear and descriptive subject line, such as "Security Vulnerability in Falcon Daemon" or "Privilege Escalation in Quarantine Manager".


📝 What to Include in Your Report

To help us validate and fix the vulnerability as quickly as possible, please include the following in your report:

  1. A Clear Description: A brief summary of the vulnerability and its potential impact.
  2. Affected Component: Specify which part of the framework is affected:
    • The Daemon Service (e.g., falcon_daemon.py, scheduler.py, updater.py)
    • The Core Scanner (e.g., scanner.py, yara_manager.py)
    • The User Interfaces (e.g., app.py (TUI), cli.py)
    • The Quarantine Vault (e.g., quarantine.py, quarantine.db)
  3. Steps to Reproduce (PoC): A clear, step-by-step guide on how an attacker could exploit the vulnerability.
  4. Environment: Your operating system, Python version, and YARA version.
  5. (Optional) Suggested Fix: If you have an idea of how to fix the issue, please let us know.

⏳ Our Commitment (What to Expect)

When you report a vulnerability to us, you can expect the following:

  1. We will respond to your report promptly, typically within 48 hours, to acknowledge we have received it.
  2. We will conduct an internal investigation to confirm the vulnerability.
  3. We will work on a patch and prepare a new release.
  4. We will keep you updated on our progress and notify you once the vulnerability is patched.
  5. We will happily give you public credit (if you wish) in the release notes for your contribution to the security of the FalconDefender community.

There aren't any published security advisories

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Remove or un-stick sticky/fixed headers that block content\n(function() {\n function unstick() {\n document.querySelectorAll('header, nav, [role=\"banner\"], .header, .navbar, .sticky, .fixed-top, [style*=\"position: fixed\"], [style*=\"position:sticky\"]').forEach(function(el) {\n if (el.style.position === 'fixed' || el.style.position === 'sticky' || \n getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') {\n el.style.position = 'static';\n el.style.top = 'auto';\n el.style.zIndex = 'auto';\n }\n });\n }\n \n unstick();\n \n var observer = new MutationObserver(unstick);\n observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] });\n})();", "Kill Sticky Headers"); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Security: Delta-Sec/FalconDefender

Security

SECURITY.md

🛡️ FalconDefender Security Policy

The FalconDefender team and the Delta-Security community take the security of this framework very seriously. We appreciate your efforts to responsibly disclose any vulnerabilities you may find.

📈 Supported Versions

Security is a rapidly evolving field, and to ensure the safety of our users, we are only able to provide security support and patches for the most recent stable version of FalconDefender.

VersionSupported
main 2.0.0 (latest)
< 1.5.0

If you are not using the latest version, please upgrade before reporting a vulnerability to ensure it has not already been fixed.


✉️ How to Report a Vulnerability

PLEASE DO NOT DISCLOSE VULNERABILITIES PUBLICLY.

Do NOT open a public GitHub Issue for a security vulnerability. This can put other users of the tool at risk.

Instead, we ask that you report all security issues privately by emailing our security contact:

Please use a clear and descriptive subject line, such as "Security Vulnerability in Falcon Daemon" or "Privilege Escalation in Quarantine Manager".


📝 What to Include in Your Report

To help us validate and fix the vulnerability as quickly as possible, please include the following in your report:

  1. A Clear Description: A brief summary of the vulnerability and its potential impact.
  2. Affected Component: Specify which part of the framework is affected:
    • The Daemon Service (e.g., falcon_daemon.py, scheduler.py, updater.py)
    • The Core Scanner (e.g., scanner.py, yara_manager.py)
    • The User Interfaces (e.g., app.py (TUI), cli.py)
    • The Quarantine Vault (e.g., quarantine.py, quarantine.db)
  3. Steps to Reproduce (PoC): A clear, step-by-step guide on how an attacker could exploit the vulnerability.
  4. Environment: Your operating system, Python version, and YARA version.
  5. (Optional) Suggested Fix: If you have an idea of how to fix the issue, please let us know.

⏳ Our Commitment (What to Expect)

When you report a vulnerability to us, you can expect the following:

  1. We will respond to your report promptly, typically within 48 hours, to acknowledge we have received it.
  2. We will conduct an internal investigation to confirm the vulnerability.
  3. We will work on a patch and prepare a new release.
  4. We will keep you updated on our progress and notify you once the vulnerability is patched.
  5. We will happily give you public credit (if you wish) in the release notes for your contribution to the security of the FalconDefender community.

There aren't any published security advisories

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Universal Dark Mode - works on any site\n(function() {\n var enabled = true;\n \n function applyDarkMode() {\n if (!enabled) return;\n \n // Create style element if it doesn't exist\n var style = document.getElementById('universal-dark-mode-style');\n if (!style) {\n style = document.createElement('style');\n style.id = 'universal-dark-mode-style';\n document.head.appendChild(style);\n }\n \n // Dark mode CSS - inverts colors but preserves images/video\n style.textContent = '\n /* Invert everything except media */\n html {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #1a1a2e !important;\n }\n \n /* Restore images, videos, iframes, canvas */\n img, video, iframe, canvas, svg, picture, [style*=\"background-image\"] {\n filter: invert(1) hue-rotate(180deg) !important;\n }\n \n /* Preserve specific elements that should not be inverted */\n .no-dark-mode, .no-dark-mode *,\n [data-theme=\"light\"], [data-theme=\"light\"],\n .ace_editor, .ace_editor *,\n .CodeMirror, .CodeMirror *,\n .monaco-editor, .monaco-editor *,\n .markdown-body pre, .markdown-body pre *,\n .highlight, .highlight *,\n pre code, pre code * {\n filter: none !important;\n }\n \n /* Fix common UI elements */\n .modal, .popup, .dropdown-menu, .tooltip, .popover {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #2d2d44 !important;\n border-color: #444 !important;\n }\n \n /* Scrollbars */\n ::-webkit-scrollbar { background: #1a1a2e !important; }\n ::-webkit-scrollbar-thumb { background: #444 !important; }\n ::-webkit-scrollbar-thumb:hover { background: #555 !important; }\n \n /* Selection */\n ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ';\n }\n \n function removeDarkMode() {\n var style = document.getElementById('universal-dark-mode-style');\n if (style) style.remove();\n }\n \n // Toggle with Alt+Shift+D\n document.addEventListener('keydown', function(e) {\n if (e.altKey && e.shiftKey && e.key === 'D') {\n e.preventDefault();\n enabled = !enabled;\n if (enabled) {\n applyDarkMode();\n console.log('[Universal Dark Mode] Enabled');\n } else {\n removeDarkMode();\n console.log('[Universal Dark Mode] Disabled');\n }\n }\n });\n \n // Apply on load\n applyDarkMode();\n \n // Re-apply on dynamic content\n var observer = new MutationObserver(function(mutations) {\n if (enabled && !document.getElementById('universal-dark-mode-style')) {\n applyDarkMode();\n }\n });\n observer.observe(document.head, { childList: true });\n \n console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle');\n})();", "Universal Dark Mode"); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })();
Skip to content

Security: Delta-Sec/FalconDefender

Security

SECURITY.md

🛡️ FalconDefender Security Policy

The FalconDefender team and the Delta-Security community take the security of this framework very seriously. We appreciate your efforts to responsibly disclose any vulnerabilities you may find.

📈 Supported Versions

Security is a rapidly evolving field, and to ensure the safety of our users, we are only able to provide security support and patches for the most recent stable version of FalconDefender.

VersionSupported
main 2.0.0 (latest)
< 1.5.0

If you are not using the latest version, please upgrade before reporting a vulnerability to ensure it has not already been fixed.


✉️ How to Report a Vulnerability

PLEASE DO NOT DISCLOSE VULNERABILITIES PUBLICLY.

Do NOT open a public GitHub Issue for a security vulnerability. This can put other users of the tool at risk.

Instead, we ask that you report all security issues privately by emailing our security contact:

Please use a clear and descriptive subject line, such as "Security Vulnerability in Falcon Daemon" or "Privilege Escalation in Quarantine Manager".


📝 What to Include in Your Report

To help us validate and fix the vulnerability as quickly as possible, please include the following in your report:

  1. A Clear Description: A brief summary of the vulnerability and its potential impact.
  2. Affected Component: Specify which part of the framework is affected:
    • The Daemon Service (e.g., falcon_daemon.py, scheduler.py, updater.py)
    • The Core Scanner (e.g., scanner.py, yara_manager.py)
    • The User Interfaces (e.g., app.py (TUI), cli.py)
    • The Quarantine Vault (e.g., quarantine.py, quarantine.db)
  3. Steps to Reproduce (PoC): A clear, step-by-step guide on how an attacker could exploit the vulnerability.
  4. Environment: Your operating system, Python version, and YARA version.
  5. (Optional) Suggested Fix: If you have an idea of how to fix the issue, please let us know.

⏳ Our Commitment (What to Expect)

When you report a vulnerability to us, you can expect the following:

  1. We will respond to your report promptly, typically within 48 hours, to acknowledge we have received it.
  2. We will conduct an internal investigation to confirm the vulnerability.
  3. We will work on a patch and prepare a new release.
  4. We will keep you updated on our progress and notify you once the vulnerability is patched.
  5. We will happily give you public credit (if you wish) in the release notes for your contribution to the security of the FalconDefender community.

There aren't any published security advisories