Skip to content

Jwt no signature verification - #1198

Open
shishir-cyber wants to merge 2 commits into
mandiant:masterfrom
shishir-cyber:jwt-no-signature-verification
Open

shishir-cyber wants to merge 2 commits into
mandiant:masterfrom
shishir-cyber:jwt-no-signature-verification

Conversation

@shishir-cyber

Copy link
Copy Markdown

Summary

Adds a new nursery rule, parse JWT without verifying signature, which detects code that parses a JWT-shaped string (base64 decode/split) without a nearby call to validate the signature - a pattern seen in custom C2/auth implementations that roll their own JWT handling to avoid detection or dependency fingerprinting.

Status

This is submitted to nursery/ rather than communication/http/ because it doesn't yet have a verified real-world sample for meta.examples. I'm actively looking for a suitable public malware sample that exhibits this pattern and will update the rule (and move it out of nursery) once I have one - happy to take pointers if anyone knows of a matching sample in capa-testfiles or elsewhere.

Linting

  • Standard lint passes cleanly (python scripts/lint.py nursery/parse-jwt-without-verifying-signature.yml → no lints failed, nice!)
  • Thorough lint (--thorough) not run locally yet, since it requires capa-testfiles and a real example to verify against - will run once an example is added

@google-cla

google-cla Bot commented Oct 3, 2026

Copy link
Copy Markdown

Thanks for your pull request! It looks like this may be your first contribution to a Google open source project. Before we can look at your pull request, you'll need to sign a Contributor License Agreement (CLA).

View this failed invocation of the CLA check for more information.

For the most up to date status, view the checks section at the bottom of the pull request.

Detects parsing of a JWT-shaped string (via base64 decode/split) without
a nearby call to verify/validate the signature — a pattern seen in
custom C2/auth implementations.

Added to nursery/ pending a verified real-world sample for `examples`.
@shishir-cyber
shishir-cyber force-pushed the jwt-no-signature-verification branch from 69ffaa7 to 33ee365 Compare October 3, 2026 17:13
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant