40 signatures watch your web-facing logs for the exploit attempts that precede a real compromise — path traversal, injection, RCE, SSRF, webshells, exposed secrets — each with a CVE reference where one applies and a specific fix, not a keyword match.
| Category | Example | What it catches |
|---|---|---|
| Reconnaissance / scanning | wp_content_plugin_probe | Automated scanners fingerprinting known CMS plugin paths |
| Injection | sqli_union_select | SQL injection attempts via UNION-based payloads |
| Injection | path_traversal_etc_passwd | Directory traversal attempts targeting system files |
| Remote code execution | rce_scan_phpunit | PHPUnit eval-stdin.php RCE probe (CVE-2017-9841) |
| Remote code execution | log4shell_jndi_probe | Log4Shell JNDI lookup injection (CVE-2021-44228) |
| SSRF | ssrf_cloud_metadata | Requests targeting 169.254.169.254-style cloud metadata endpoints |
| Webshell | webshell_upload_attempt | File uploads matching known webshell signatures |
| Exposed secrets | exposed_dotenv | Requests for .env, .git, or composer.json under the web root |
Security hits use the same signature engine as every other layer of Kllyroo — a match is a named, specific finding with a confidence score, not a generic "suspicious activity" flag.
That click is the approval — a human decision made in context, looking at the actual hit, not a background process guessing at intent.
Same human-approved command queue used for agent updates — see Automated Response for the mechanism.
The block is enforced on the affected server itself, right where the traffic is landing.
Every block is visible and can be undone with the same one-click, human-approved flow — no silent, permanent lockouts from a false positive.
Offices in India and the US — reach out and we'll get back to you.