Security

Catches the scan, not just the breach.

40 signatures watch your web-facing logs for the exploit attempts that precede a real compromise — path traversal, injection, RCE, SSRF, webshells, exposed secrets — each with a CVE reference where one applies and a specific fix, not a keyword match.

40security signatures
6threat categories
1click to block, human-approved
Coverage

40 signatures, six categories.

CategoryExampleWhat it catches
Reconnaissance / scanningwp_content_plugin_probeAutomated scanners fingerprinting known CMS plugin paths
Injectionsqli_union_selectSQL injection attempts via UNION-based payloads
Injectionpath_traversal_etc_passwdDirectory traversal attempts targeting system files
Remote code executionrce_scan_phpunitPHPUnit eval-stdin.php RCE probe (CVE-2017-9841)
Remote code executionlog4shell_jndi_probeLog4Shell JNDI lookup injection (CVE-2021-44228)
SSRFssrf_cloud_metadataRequests targeting 169.254.169.254-style cloud metadata endpoints
Webshellwebshell_upload_attemptFile uploads matching known webshell signatures
Exposed secretsexposed_dotenvRequests for .env, .git, or composer.json under the web root

Confidence score, CVE, and fix — every time.

Security hits use the same signature engine as every other layer of Klyroo — a match is a named, specific finding with a confidence score, not a generic "suspicious activity" flag.

GET /wp-content/plugins/x/eval-stdin.php HTTP/1.1
MATCH · rce_scan_phpunitConfidence 95%
Exploit scan detected: probing for the PHPUnit eval-stdin.php RCE vulnerability (CVE-2017-9841).
Fix: confirm PHPUnit isn't exposed under the web root in production.
Response

One click to block. Never automatic.

You click "Block this IP" on the alert

That click is the approval — a human decision made in context, looking at the actual hit, not a background process guessing at intent.

The action is queued to that specific server

Same human-approved command queue used for agent updates — see Automated Response for the mechanism.

The agent applies it on its next check-in

The block is enforced on the affected server itself, right where the traffic is landing.

It shows up in a "Blocked IPs" tab, reversible anytime

Every block is visible and can be undone with the same one-click, human-approved flow — no silent, permanent lockouts from a false positive.

Where We Stand

Scope, honestly.

What's covered

  • 40 signatures across recon, injection, RCE, SSRF, webshell, and exposed-secret categories
  • CVE references attached where one exists
  • One-click, human-approved IP blocking straight from the alert
  • Full reversibility — a Blocked IPs tab with unblock built in

What it isn't

  • Not an inline WAF — detection works off request patterns already in your web-facing logs, so it responds after a request lands, not before
  • Blocking is never automatic by design, which means the fastest possible response still requires a person to click — a deliberate trade against the risk of self-inflicted lockouts
Pairs Well With

Related capabilities

See the scan before it becomes a breach.

Point one agent at a web-facing server and watch a real signature match.

Book a 20-minute demo