RemarkableCloud

Imunify360: Overview & Key Features

How Imunify360 protects your RemarkableCloud managed VPS: firewall, malware scanner, Proactive Defense, and handling incidents from WHM.

Imunify360 is the security suite installed on all RemarkableCloud cPanel and DirectAdmin servers. It combines a web application firewall, malware scanner, intrusion detection, and reputation management into a single system that runs automatically: blocking attacks and cleaning infections without manual intervention.

What Imunify360 protects against

ThreatHow Imunify360 handles it
Brute-force attacksAuto-blocks IPs after repeated failed logins
Malware and web shellsScans files on upload and on schedule, quarantines threats
Drive-by exploitsPatches vulnerabilities at server level before the app is updated
DDoS and flood attacksRate-limits abusive traffic at the network edge
Compromised accountsDetects accounts sending spam or serving malware
Zero-day exploitsProactive Defense intercepts suspicious PHP execution in real time

Accessing Imunify360

Log into WHM → search Imunify360Plugins → Imunify360.

The firewall

ListPurpose
Black listIPs permanently blocked from the server
Gray listIPs challenged with CAPTCHA before being allowed through
White listIPs always allowed: bypasses all rules

Managing the firewall

  • Go to Imunify360 → Firewall.
  • Select the tab: Black List, Gray List, or White List.
  • To add an IP: click Add, enter the IP or CIDR range, add a comment, click Add IP.
  • To remove: find the IP and click Delete.
  • Always confirm an IP is legitimate before whitelisting. Imunify360 blocks based on attack signatures: removing a block without understanding why can expose your server.

    Malware scanner

    Imunify360 scans three ways: on-demand (you trigger manually), scheduled (daily by default), and real-time (monitors file changes as they happen).

    Running a manual scan

  • Go to Imunify360 → Malware Scanner.
  • Click Scan: choose All for the full server or User for a specific account.
  • Click Start Scan. Large servers may take 30-60 minutes.
  • Results appear in the Infected Files tab.
  • Handling infected files

    ActionWhat it does
    CleanupRemoves only malicious code, leaves the clean file intact
    QuarantineMoves file to sandbox where it cannot execute
    DeletePermanently removes the file

    Use Cleanup first. If the file cannot be cleaned safely, Imunify360 falls back to quarantine automatically.

    Proactive Defense

    Proactive Defense monitors PHP execution in real time and blocks malicious behavior as it happens: even from malware that has never been seen before. It watches what PHP does, not just what it looks like.

    ModeBehavior
    DisabledOff
    LogLogs suspicious activity without blocking (use for tuning)
    KillTerminates malicious PHP processes immediately

    Set mode under Imunify360 → Proactive Defense → Settings.

    Proactive Defense runs in Kill mode by default on all managed Cloud Cubes. No configuration needed.

    Common situations

    Client locked out of WordPress admin Their IP was graylisted after failed logins. Go to Firewall → Gray List, find their IP, and move it to the white list temporarily. Help them reset their WordPress password afterwards.

    Legitimate file being quarantined Go to Malware Scanner → Quarantined, find the file, click Restore. Add a path exclusion under Settings → Malware Scanner → Ignore List to prevent it happening again.

    Site flagged as malware by Google

    1. Run a manual scan on the account
    2. Clean all infected files
    3. Scan again to confirm clean
    4. Submit a review request via Google Search Console → Security Issues

    Imunify360 blocking legitimate file uploads Go to Settings → Web Application Firewall and add a rule exception for the specific URL or file type.

    Next steps

    Still stuck? Ask a human, we answer in minutes.