Everything You Need to
Protect Your Servers

Six integrated security modules working together to provide complete server protection. No configuration required — just install and forget.

Explore Modules ↓

Login Failure Daemon

Monitors authentication logs across 20+ services in real time. Automatically blocks brute force attackers before they compromise accounts.

SSHD, FTP, SMTP, IMAP, cPanel & more

Dynamic Firewall

Production-ready iptables firewall with secure-by-default port settings. Easy customization through the configuration file.

IPv4 + IPv6 · Auto port discovery

DDoS Mitigation

Connection-based DoS protection at L3/L4 with per-IP connection limits, port flood detection, and ICMP rate limiting.

Per-IP limits · Cloudflare API

Alerting & Notifications

Configurable per-event-type email alerts with custom templates and external script hooks.

Email

Intrusion Detection

Detects port scans, exploit attempts, and suspicious processes. Regex-based pattern matching identifies known attack signatures.

Port scan · Exploit · Process monitoring

Account Hardening

Alerts on new account creation, monitors file integrity, and detects deleted-binary processes across all accounts.

File integrity · Policy enforcement

How Each Module Protects You

Detailed breakdown of every component in the SecLayer security stack.

Core Engine

Login Failure Daemon (LFD)

The heart of SecLayer. LFD continuously monitors system authentication logs and tracks failed login attempts by IP. When thresholds are exceeded, offenders are automatically blocked at the firewall level — no human intervention required.

  • Real-time log monitoring on all configured log files
  • Per-service tracking: SSH, FTP, SMTP, POP3, IMAP, cPanel, Webmail
  • Configurable thresholds, block durations, and permanent lists
  • Automatic cleanup with graduated blocking for repeat offenders
  • PTR lookup with regex pattern matching on offending IPs
LFD Activity
[14:32:01] LF_SSHD: 203.0.113.42 — 12 failures in 60s [14:32:01] BLOCKED: 203.0.113.42 added to iptables [14:31:45] LF_FTPD: 198.51.100.17 — 8 failures [14:31:05] Monitoring: 12 active connections on port 22
Firewall Status
Chain INPUT (policy DROP) ACCEPT tcp -- 0.0.0.0/0 tcp dpt:22 ACCEPT tcp -- 0.0.0.0/0 tcp dpt:80 DROP all -- 203.0.113.42 DROP all -- 198.51.100.17
Network Layer

Dynamic Firewall Management

Automatically discovers open ports and generates precise iptables rules. No manual rule writing — the firewall configures itself based on your running services.

  • Full IPv4 and IPv6 with stateful connection tracking
  • Custom allow, deny, and ignore lists for IPs and ports
  • SYN flood protection via configurable connection thresholds
Attack Surface

Multi-Layer DDoS Protection

The DDoS daemon monitors connection rates and applies per-IP limits automatically. Port flood detection and ICMP rate limiting protect against volumetric attacks at the network layer.

  • SYN flood detection via port-based connection limits
  • Per-IP connection tracking with permanent block for repeat offenders
  • ICMP flood protection
  • Cloudflare API integration for edge-level protection
ddos.conf
# /etc/seclayer/ddos.conf DDOS_ENABLE="1" DDOS_INTERVAL="60" NO_OF_CONNECTIONS="150" BAN_PERIOD="600" ENABLE_PORTS="true" PORT_CONNECTIONS="80:150:600 443:150:600"

Works With Your Control Panel

Native integration with every major hosting platform. Features activate automatically when detected during installation.

cPanel / WHM

Coming Soon

DirectAdmin

Coming Soon

Plesk

Coming Soon

InterWorx

Coming Soon

CWP

Coming Soon

Contact SecLayer

For sales inquiries, reach out to us at

Email Now →

Or email support@seclayer.net for technical support.