← Back Products

DirektShield – automated bot protection for DirectAdmin servers

Shared hosting servers rarely go down because of one attacker. They go down because hundreds of bots, scanners and crawlers occupy every PHP worker at the same time. DirektShield analyses the traffic of all domains on the server every minute, recognises abuse patterns and blocks the source in CSF before the load climbs.

What it detects

  • Vulnerability scanners, PHP shells, probes for non-existent files
  • Brute-force on wp-login, xmlrpc and forms, including captcha floods
  • Floods on admin-ajax, wp-json, site search and shop filters (WooCommerce, PrestaShop)
  • SQL injection, path traversal, abusive HTTP methods
  • Aggressive crawlers (AI, SEO) and botnets spread across whole subnets
  • Repeat offenders — IPs blocked repeatedly are moved to a permanent ban automatically

Why it won’t lock out your customers

  • Logged-in WordPress administrators are recognised automatically and exempted
  • Separate thresholds for local traffic, Google/Bing and the rest of the world
  • CSF whitelists and your own customer IP lists are honoured, including CIDR ranges
  • Dry-run mode shows exactly what would be blocked, without blocking anything

Technical

  • Native IPv4 and IPv6, blocking by IP or by prefix (/24, /48)
  • Incremental log reading — under 1 second per run on servers with 200 domains
  • 18 independent modules, each with thresholds set in a single config file
  • No dependencies: bash, awk, CSF, GeoIP — nothing extra to install
  • DirectAdmin with nginx + Apache

Delivery: installed and calibrated on your server by the DirektSupport team, with a dry-run monitoring period before activation.