Skip to content

Rootkit and IP reputation checks

cPFence v4+ rootkit checks look for suspicious system activity. IP reputation checks ask AbuseIPDB about the server’s public IP. Both are advisory: they do not automatically remove a rootkit or block the server IP.

Administrators can change these settings. Support users need target-server access and the relevant Detection or General Settings permissions. Root commands require root access and the applicable license.

  1. Open Threat & Malware Detection and choose the server scope.
  2. Click Settings and set Daily Rootkit Scanner.
  3. Click Save and confirm the saved value.

You can also search for Daily rootkit scan in System Settings. For several servers, use Advanced Tools → Manage Rootkit Scanner, check the sidebar bulk targets, and choose Enable Rootkit Scanner or Disable Rootkit Scanner. Read each target’s result.

The fresh default is on. Enabling scheduled checks does not mean a new check has completed. Disabling them does not remove suspicious software or old findings.

Detection Settings showing Daily Rootkit Scanner, separate email controls and the Save button.

Daily Rootkit Scanner and Save controls. Shown values are existing settings, not fresh defaults or completed checks. Select the image for full size; use browser Back to return.

For the Detection page’s defaults, follow reset feature-page settings.

  1. Open System Settings → General Settings and select the server.
  2. Search for IP reputation monitoring and set the switch.
  3. Click Save changes and confirm the saved value.

General Settings showing the IP reputation monitoring switch for the selected server, with Save changes.

IP reputation monitoring setting. A saved switch does not establish a completed check or a clean reputation score. Select the image for full size; use browser Back to return.

The fresh default is on. A positive AbuseIPDB score produces an advisory. A valid zero score means the provider did not flag that IP at that observation; it is not a delivery or security guarantee. Provider limits, timeouts, and interrupted checks are unknown results, not clean scores.

For recorded rootkit checks, findings and manual runs, follow Rootkit Scans. Its results are separate from the IP reputation observations below.

On System Dashboard, open alerts and filter by Rootkit or IP reputation. Check the server, observation time, and finding. Email/Slack destinations are under Notification Settings.

A root administrator can read recent service output:

Terminal window
journalctl -u cpfcli-rootkit.service -n 100 --no-pager
journalctl -u cpfcli-ip-reputation.service -n 100 --no-pager

Private reports are under /var/lib/cpfcli/rootkit/ and /var/lib/cpfcli/ip-reputation/. An incomplete check can retain partial findings; it is not an all-clear. Investigate the named software, website activity, or outbound mail before deleting anything.

If a report is missing, confirm the saved switch and inspect the service error. Provider backoff can postpone reputation checks. Use malware scans or Vulnerability Manager for further investigation; use firewall policy only when you intend an actual access change.