RemarkableCloud

Imunify360: Overview & Key Features

How Imunify360 protects your RemarkableCloud managed VPS: firewall, malware scanner, Proactive Defense, and handling incidents from WHM.

Updated August 2026

Imunify360 is the security suite installed on all RemarkableCloud cPanel and DirectAdmin servers. It combines a web application firewall, malware scanner, intrusion detection, and reputation management into a single system that runs automatically: blocking attacks and cleaning infections without manual intervention.

What Imunify360 protects against

ThreatHow Imunify360 handles it
Brute-force attacksAuto-blocks IPs after repeated failed logins
Malware and web shellsScans files on upload and on schedule, quarantines threats
Drive-by exploitsPatches vulnerabilities at server level before the app is updated
DDoS and flood attacksRate-limits abusive traffic at the network edge
Compromised accountsDetects accounts sending spam or serving malware
Zero-day exploitsProactive Defense intercepts suspicious PHP execution in real time

Accessing Imunify360

Log into WHM → search Imunify360Plugins → Imunify360.

The firewall

ListPurpose
Black listIPs permanently blocked from the server
Gray listIPs challenged with CAPTCHA before being allowed through
White listIPs always allowed: bypasses all rules

Managing the firewall

  1. Go to Imunify360 → Firewall.
  2. Select the tab: Black List, Gray List, or White List.
  3. To add an IP: click Add, enter the IP or CIDR range, add a comment, click Add IP.
  4. To remove: find the IP and click Delete.

Investigate before whitelisting: Always confirm an IP is legitimate before whitelisting. Imunify360 blocks based on attack signatures: removing a block without understanding why can expose your server.

Malware scanner

Imunify360 scans three ways: on-demand (you trigger manually), scheduled (daily by default), and real-time (monitors file changes as they happen).

Running a manual scan

  1. Go to Imunify360 → Malware Scanner.
  2. Click Scan: choose All for the full server or User for a specific account.
  3. Click Start Scan. Large servers may take 30-60 minutes.
  4. Results appear in the Infected Files tab.

Handling infected files

ActionWhat it does
CleanupRemoves only malicious code, leaves the clean file intact
QuarantineMoves file to sandbox where it cannot execute
DeletePermanently removes the file

Use Cleanup first. If the file cannot be cleaned safely, Imunify360 falls back to quarantine automatically.

Proactive Defense

Proactive Defense monitors PHP execution in real time and blocks malicious behavior as it happens: even from malware that has never been seen before. It watches what PHP does, not just what it looks like.

ModeBehavior
DisabledOff
LogLogs suspicious activity without blocking (use for tuning)
KillTerminates malicious PHP processes immediately

Set mode under Imunify360 → Proactive Defense → Settings.

On RemarkableCloud servers: Proactive Defense runs in Kill mode by default on all managed Cloud Cubes. No configuration needed.

Common situations

Client locked out of WordPress admin Their IP was graylisted after failed logins. Go to Firewall → Gray List, find their IP, and move it to the white list temporarily. Help them reset their WordPress password afterwards.

Legitimate file being quarantined Go to Malware Scanner → Quarantined, find the file, click Restore. Add a path exclusion under Settings → Malware Scanner → Ignore List to prevent it happening again.

Site flagged as malware by Google

  1. Run a manual scan on the account
  2. Clean all infected files
  3. Scan again to confirm clean
  4. Submit a review request via Google Search Console → Security Issues

Imunify360 blocking legitimate file uploads Go to Settings → Web Application Firewall and add a rule exception for the specific URL or file type.

Next steps

Still stuck? Ask a human, we answer in minutes.