What it detects
What it detects
SSH & brute force
15 detection patterns in the SSH log: failed passwords, invalid users, PAM failures, pre-auth scanning, protocol mismatches, key-exchange drops. Attackers are banned at the firewall for escalating durations — 24 hours, 7 days, 30 days, then permanent — or for the duration you choose.
Web Application Firewall
| Attack type | Score | Mode |
|---|---|---|
| RCE / Web shell / Shellshock | +50 | Score-based |
| Scanner UA (sqlmap, nikto, nmap, nuclei…) | +50 | Score-based |
| SQL injection / SSRF / Web exploit | +40 | Score-based |
| Honeypot trap (decoy paths you define) | +40 | Score-based |
| Path traversal / Header injection | +30 | Score-based |
| WordPress brute force | +30 | Threshold (10 req / 2 min) |
| XSS / .env probe / XMLRPC | +25 | Score-based |
| Config probing | +20 | Score-based |
| 404 flood | +15 | Threshold (15 req / 5 min) |
Each detection adds points to the visitor's score, which decays by 5 points per minute. Action levels: observe (30) → slow down (60) → block (80) → firewall ban (100). From the dashboard you can see every built-in rule, change weights, thresholds and per-type mode, turn off single patterns and add your own rules.
Bot management
About 1,500 bots recognized from public lists updated daily — search engines, AI crawlers, SEO tools, scanners, monitoring, link previews and more. Fake search-engine bots are unmasked through their address. For each category, or each single bot, you choose: allow, log only or block — and every bot comes with a plain-language explanation.
Malware scanner
- Signature scanning — 28 built-in patterns for web shells, backdoors, crypto miners and phishing kits
- YARA engine — community rules for web threats, refreshed daily (needs the yara tool, installable with one click from the dashboard)
- Every finding explains why it matched, how severe it is and the file's SHA-256, with links to check it on public malware databases
- Framework detection — WordPress, Laravel, Django, Symfony, CakePHP, CodeIgniter, Node/Express, Rails, Joomla, Drupal
- Framework security checks — .env exposure, DEBUG mode, APP_KEY, loose permissions, Telescope, wp-config
- Heuristics — Shannon entropy detection, timestamp anomalies in upload directories
- System integrity — modified system binaries (dpkg -V / rpm -Va), rootkit indicators
- Credential scan — exposed .env files, SSH key permissions, .git in the web root, cloud credentials
- WordPress database scan — injected scripts in posts and options, rogue admin users
- Process detection — running crypto miners, reverse shells, suspicious scripts from /tmp
- Quarantine — one click moves a malicious file to quarantine, from where it can be restored
- Ignore — mark a false positive once and future scans skip it
- Scheduled scans every 3, 6, 12 or 24 hours, plus "Scan now" from the dashboard
- Real-time watcher — checks upload directories every 30 seconds for new PHP files
- False-positive prevention — WordPress core checksums, context-based severity
ModSecurity inline WAF (optional)
- Only when you allow web server changes in Settings — off by default
- Never on servers whose configuration is managed by a hosting panel or a configuration-management tool
- For Apache with mod_security2
- 13 rules — SQL injection, XSS, RCE, SSRF, path traversal, Shellshock, Log4Shell, Spring4Shell, scanner blocking
- Blocks on the first request, before traffic reaches your application
- Safe: if Apache's configuration test fails, the change is rolled back
- Active bans are enforced by ModSecurity too, for visitors behind a proxy or CDN
Outbound and DNS threat detection
Key differentiatorMost tools only watch traffic coming in. InfraFence also watches what the server does going out, to catch a compromised machine talking to its controllers:
- Outbound connections to IPs on public threat-intelligence lists
- DNS inspection — every DNS query is read (without changing anything) and tied to the program that made it: queries to unexpected or malicious DNS servers, domains that resolve to known malicious IPs, DNS tunnels, and malware generating random domains (DGA)
- The server's own DNS service and antivirus or anti-spam lookups are recognized and not reported
File integrity & persistence monitoring
SHA-256 baseline hashing with instant alerts on change, covering both classic tripwire targets and common persistence techniques:
- Core system files — /etc/passwd, /etc/shadow, /etc/group, /etc/sudoers (+ sudoers.d/*), /etc/ssh/sshd_config, /etc/hosts, /etc/resolv.conf
- Scheduled-task persistence — /etc/crontab, /etc/cron.d/*, and per-user crontabs
- SSH persistence — authorized_keys for root and every user under /home/*
- Rootkit / hijack points — /etc/ld.so.preload (classic userspace LD_PRELOAD hijack)
- Systemd persistence — /etc/systemd/system/*.service and *.timer
SSH session risk scoring
Key differentiatorTracks every SSH session end-to-end — auth method, source IP reputation, login hour, privileged commands (sudo, useradd, passwd, crontab, su) — and scores it 0-100 on close. Sigma correlation: if any other detector (WAF, integrity, malware, port scan, egress, DNS) fires while a session is open, that session's risk score jumps — turning scattered low-confidence signals into one high-confidence alert tied to exactly who was logged in when it happened.
Hardening, vulnerabilities and security score
Key differentiatorBeyond attacks, InfraFence checks how exposed the server itself is — every day, or on request from the dashboard:
- About 40 hardening checks — SSH settings, permissions of sensitive files, databases open to the internet, accounts, web server settings, exposed secrets, outdated software
- One-click fixes for the safe ones: each change goes in a file of its own, is tested before the service is reloaded and can be undone. Changes that could lock you out or break a site are explained step by step instead
- Known vulnerabilities (CVE) of the installed packages, from the Debian, Ubuntu, AlmaLinux and Rocky Linux security trackers — what an update fixes now, apart from what has no fix yet
- A security score from 0 to 100, showing what lowers it
And more
- Mail, database and FTP protection — brute force detection for Postfix, Dovecot, MySQL, PostgreSQL, MongoDB, Pure-FTPd, ProFTPD and vsftpd
- Docker-aware — finds web containers' logs and protects published container ports
- Country blocking from the dashboard
- Hosting panels recognized — cPanel/WHM, Plesk, DirectAdmin, CyberPanel, HestiaCP, Coolify, Easypanel and 17 more; InfraFence never edits a configuration a panel manages
- LiteSpeed and OpenLiteSpeed recognized
- Dashboard changes reach your servers in about a second
- Monitor mode — detect everything, block nothing
- System metrics — CPU, memory, disk and network
- Every event explained in plain language, in 6 languages
- Optional: an address banned on one server is banned on all your servers
What you get
| InfraFence | |
|---|---|
| Live dashboard for all your servers | Yes, updated in real time |
| Install | One command, with a read-only check first |
| SSH brute force | 15 patterns, escalating bans |
| SSH session risk scoring | Yes, correlated with every other detector |
| Web application firewall | 15 attack types, editable from the dashboard |
| Bots | ~1,500 recognized; allow, log or block per category or bot |
| Malware | Signatures + YARA, with quarantine and ignore |
| File integrity & persistence | System-wide |
| Outbound & DNS threats | DNS inspected packet by packet, tied to the program |
| Docker | Yes: container logs and published ports |
| Monitor mode (detect only) | Yes |
| Uninstall | Removes everything it added |
| Price | €9/server/month, 1 server free |
Security & trust
Running this agent means granting it privileged access to your server — that's a real ask, and we don't take it lightly. Here's exactly what backs that trust in production:
- Open source
- The agent is MIT licensed. Audit every line before installing.
- Checks before it changes
- A read-only scan of the server runs before installation and every day. Web server changes and threat-list blocking stay off until you turn them on, and never happen where a hosting panel manages the configuration.
- What it reads
- To detect threats it reads system and web server logs, website files for the malware scan (including .env and configuration files), WordPress posts and users for the WordPress scan, and the server's DNS traffic and network connections.
- What it sends
- Security events only: attacker IP, type, time and the details needed to understand them — for a web attack the single log line that triggered it, for malware the file path and the matched text. Full logs and files never leave your server. No telemetry, no third-party sharing.
- Dedicated firewall chain
- All its rules live in its own INFRAFENCE chains, repaired automatically if another tool removes them. Your existing rules are never modified.
- Signed binaries
- Every release is built by GitHub Actions CI with Cosign signatures and build provenance attestation.
- Monitor mode
- Detect everything, block nothing — enable protection when you're ready.
- Clean uninstall
- One command removes the agent and everything it added: firewall chains, web server changes and the service.
