InfraFenceInfraFence

Live Security Operations

Sign inGet Started

What it detects

What it detects

SSH & brute force

15 detection patterns in the SSH log: failed passwords, invalid users, PAM failures, pre-auth scanning, protocol mismatches, key-exchange drops. Attackers are banned at the firewall for escalating durations — 24 hours, 7 days, 30 days, then permanent — or for the duration you choose.

Web Application Firewall

Attack typeScoreMode
RCE / Web shell / Shellshock+50Score-based
Scanner UA (sqlmap, nikto, nmap, nuclei…)+50Score-based
SQL injection / SSRF / Web exploit+40Score-based
Honeypot trap (decoy paths you define)+40Score-based
Path traversal / Header injection+30Score-based
WordPress brute force+30Threshold (10 req / 2 min)
XSS / .env probe / XMLRPC+25Score-based
Config probing+20Score-based
404 flood+15Threshold (15 req / 5 min)

Each detection adds points to the visitor's score, which decays by 5 points per minute. Action levels: observe (30) → slow down (60) → block (80) → firewall ban (100). From the dashboard you can see every built-in rule, change weights, thresholds and per-type mode, turn off single patterns and add your own rules.

Bot management

About 1,500 bots recognized from public lists updated daily — search engines, AI crawlers, SEO tools, scanners, monitoring, link previews and more. Fake search-engine bots are unmasked through their address. For each category, or each single bot, you choose: allow, log only or block — and every bot comes with a plain-language explanation.

Malware scanner

  • Signature scanning — 28 built-in patterns for web shells, backdoors, crypto miners and phishing kits
  • YARA engine — community rules for web threats, refreshed daily (needs the yara tool, installable with one click from the dashboard)
  • Every finding explains why it matched, how severe it is and the file's SHA-256, with links to check it on public malware databases
  • Framework detection — WordPress, Laravel, Django, Symfony, CakePHP, CodeIgniter, Node/Express, Rails, Joomla, Drupal
  • Framework security checks — .env exposure, DEBUG mode, APP_KEY, loose permissions, Telescope, wp-config
  • Heuristics — Shannon entropy detection, timestamp anomalies in upload directories
  • System integrity — modified system binaries (dpkg -V / rpm -Va), rootkit indicators
  • Credential scan — exposed .env files, SSH key permissions, .git in the web root, cloud credentials
  • WordPress database scan — injected scripts in posts and options, rogue admin users
  • Process detection — running crypto miners, reverse shells, suspicious scripts from /tmp
  • Quarantine — one click moves a malicious file to quarantine, from where it can be restored
  • Ignore — mark a false positive once and future scans skip it
  • Scheduled scans every 3, 6, 12 or 24 hours, plus "Scan now" from the dashboard
  • Real-time watcher — checks upload directories every 30 seconds for new PHP files
  • False-positive prevention — WordPress core checksums, context-based severity

ModSecurity inline WAF (optional)

  • Only when you allow web server changes in Settings — off by default
  • Never on servers whose configuration is managed by a hosting panel or a configuration-management tool
  • For Apache with mod_security2
  • 13 rules — SQL injection, XSS, RCE, SSRF, path traversal, Shellshock, Log4Shell, Spring4Shell, scanner blocking
  • Blocks on the first request, before traffic reaches your application
  • Safe: if Apache's configuration test fails, the change is rolled back
  • Active bans are enforced by ModSecurity too, for visitors behind a proxy or CDN

Outbound and DNS threat detection

Key differentiator

Most tools only watch traffic coming in. InfraFence also watches what the server does going out, to catch a compromised machine talking to its controllers:

  • Outbound connections to IPs on public threat-intelligence lists
  • DNS inspection — every DNS query is read (without changing anything) and tied to the program that made it: queries to unexpected or malicious DNS servers, domains that resolve to known malicious IPs, DNS tunnels, and malware generating random domains (DGA)
  • The server's own DNS service and antivirus or anti-spam lookups are recognized and not reported

File integrity & persistence monitoring

SHA-256 baseline hashing with instant alerts on change, covering both classic tripwire targets and common persistence techniques:

  • Core system files — /etc/passwd, /etc/shadow, /etc/group, /etc/sudoers (+ sudoers.d/*), /etc/ssh/sshd_config, /etc/hosts, /etc/resolv.conf
  • Scheduled-task persistence — /etc/crontab, /etc/cron.d/*, and per-user crontabs
  • SSH persistence — authorized_keys for root and every user under /home/*
  • Rootkit / hijack points — /etc/ld.so.preload (classic userspace LD_PRELOAD hijack)
  • Systemd persistence — /etc/systemd/system/*.service and *.timer

SSH session risk scoring

Key differentiator

Tracks every SSH session end-to-end — auth method, source IP reputation, login hour, privileged commands (sudo, useradd, passwd, crontab, su) — and scores it 0-100 on close. Sigma correlation: if any other detector (WAF, integrity, malware, port scan, egress, DNS) fires while a session is open, that session's risk score jumps — turning scattered low-confidence signals into one high-confidence alert tied to exactly who was logged in when it happened.

Hardening, vulnerabilities and security score

Key differentiator

Beyond attacks, InfraFence checks how exposed the server itself is — every day, or on request from the dashboard:

  • About 40 hardening checks — SSH settings, permissions of sensitive files, databases open to the internet, accounts, web server settings, exposed secrets, outdated software
  • One-click fixes for the safe ones: each change goes in a file of its own, is tested before the service is reloaded and can be undone. Changes that could lock you out or break a site are explained step by step instead
  • Known vulnerabilities (CVE) of the installed packages, from the Debian, Ubuntu, AlmaLinux and Rocky Linux security trackers — what an update fixes now, apart from what has no fix yet
  • A security score from 0 to 100, showing what lowers it

And more

  • Mail, database and FTP protection — brute force detection for Postfix, Dovecot, MySQL, PostgreSQL, MongoDB, Pure-FTPd, ProFTPD and vsftpd
  • Docker-aware — finds web containers' logs and protects published container ports
  • Country blocking from the dashboard
  • Hosting panels recognized — cPanel/WHM, Plesk, DirectAdmin, CyberPanel, HestiaCP, Coolify, Easypanel and 17 more; InfraFence never edits a configuration a panel manages
  • LiteSpeed and OpenLiteSpeed recognized
  • Dashboard changes reach your servers in about a second
  • Monitor mode — detect everything, block nothing
  • System metrics — CPU, memory, disk and network
  • Every event explained in plain language, in 6 languages
  • Optional: an address banned on one server is banned on all your servers

What you get

InfraFence
Live dashboard for all your serversYes, updated in real time
InstallOne command, with a read-only check first
SSH brute force15 patterns, escalating bans
SSH session risk scoringYes, correlated with every other detector
Web application firewall15 attack types, editable from the dashboard
Bots~1,500 recognized; allow, log or block per category or bot
MalwareSignatures + YARA, with quarantine and ignore
File integrity & persistenceSystem-wide
Outbound & DNS threatsDNS inspected packet by packet, tied to the program
DockerYes: container logs and published ports
Monitor mode (detect only)Yes
UninstallRemoves everything it added
Price€9/server/month, 1 server free

Security & trust

Running this agent means granting it privileged access to your server — that's a real ask, and we don't take it lightly. Here's exactly what backs that trust in production:

Open source
The agent is MIT licensed. Audit every line before installing.
Checks before it changes
A read-only scan of the server runs before installation and every day. Web server changes and threat-list blocking stay off until you turn them on, and never happen where a hosting panel manages the configuration.
What it reads
To detect threats it reads system and web server logs, website files for the malware scan (including .env and configuration files), WordPress posts and users for the WordPress scan, and the server's DNS traffic and network connections.
What it sends
Security events only: attacker IP, type, time and the details needed to understand them — for a web attack the single log line that triggered it, for malware the file path and the matched text. Full logs and files never leave your server. No telemetry, no third-party sharing.
Dedicated firewall chain
All its rules live in its own INFRAFENCE chains, repaired automatically if another tool removes them. Your existing rules are never modified.
Signed binaries
Every release is built by GitHub Actions CI with Cosign signatures and build provenance attestation.
Monitor mode
Detect everything, block nothing — enable protection when you're ready.
Clean uninstall
One command removes the agent and everything it added: firewall chains, web server changes and the service.