BashEdge Demo
BashEdge
v0.12.89watching for 18 days
- Passed 72%
- Challenged 18%
- Blocked 10%
Source IPs
203.0.113.472,81912.1%198.51.100.225522.4%192.0.2.814501.9%203.0.113.1083451.5%198.51.100.1512401.0%Hosts
storefront.example6,31027.0%portal.example2,69911.6%api.example1,7567.5%docs.example9053.9%accounts.example7353.1%Countries
US12,31952.8%GB3,01012.9%SG2,96812.7%FR8533.7%DE7163.1%Source ASNs
64500 (EXAMPLE-CDN)7,10130.4%64501 (EDGE-NET)2,88012.3%64502 (CLOUD-DEMO)1,2175.2%64503 (TRANSIT-GB)1,0544.5%64504 (HOSTING-EU)9504.1%User agents
Mozilla/5.0 (Windows NT 10.0; Win64; x64) Chrome/145 Safari/537.363,83416.4%Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) Chrome/145 Safari/537.361,9708.4%Mozilla/5.0 (Linux; Android 14) Chrome/151 Mobile Safari/537.361,1955.1%SearchCrawler/1.0 (+https://crawler.example/bot)7313.1%Cache Preload/2.46652.8%Status codes
20016,44470.4%3013,03513.0%4041,8728.0%5039514.1%3042571.1%Source subnets
192.0.2.0/246,63428.4%203.0.113.0/242,81912.1%198.51.100.0/245522.4%2001:db8:1200::/484782.0%2001:db8:3400::/484541.9%Device types
Bot11,02547.2%Desktop4,70420.1%Mobile4,37618.7%Other3,08813.2%Script900.4%Browsers
Other bot8,88838.1%Chrome3,75316.1%Unknown/Other3,17913.6%Safari2,53110.8%Chrome Mobile1,8688.0%Operating systems
Windows6,76829.0%Unknown/Other6,03325.8%macOS3,95416.9%iOS2,62011.2%Android2,42210.4%Methods
GET20,77989.0%POST2,2209.5%HEAD3471.5%Referers
Direct / none14,78663.3%https://search.example/results/4181.8%https://storefront.example/2641.1%https://portal.example/account/2591.1%https://docs.example/guides/2160.9%Paths
/shop/page/8/2,35610.1%/wp-cron.php1,3075.6%/1,2355.3%/shop/page/2/8713.7%/shop/7753.3%Recent decisions from the agent, newest first.
Every row below uses reserved example addresses and synthetic rule results.
| Time | Address | Network | Action | Reason | Rule | |
|---|---|---|---|---|---|---|
| now | 203.0.113.68 | EXAMPLE-NET | Challenged | User agent issue | BE-120 · no-user-agent | |
| 1 min | 198.51.100.177 | EDGE-EU | Blocked | WordPress REST endpoint probing | BE-214 · wp-rest-probe | |
| 1 min | 192.0.2.17 | CRAWLER-DEMO | Challenged | Distributed request rate exceeded | BE-308 · distributed-request-rate | |
| 1 min | 2001:db8::44 | EDGE-US | Blocked | Credential and configuration file probing | BE-142 · credential-file-probe | |
| 2 min | 203.0.113.39 | TRANSIT-GB | Challenged | Script-like browser request rate | BE-126 · browser-ua-script-rate | |
| 2 min | 198.51.100.49 | CLOUD-DEMO | Blocked | SQL injection payload in the URL | BE-204 · query-sql-injection | |
| 2 min | 192.0.2.27 | HOSTING-EU | Challenged | Repeated requests across missing paths | BE-173 · path-probing | |
| 3 min | 203.0.113.25 | EXAMPLE-NET | Blocked | Remote code execution payload | BE-233 · remote-code-execution | |
| 4 min | 198.51.100.29 | EDGE-EU | Passed | Browser completed visitor verification | BE-001 · challenge-passed | |
| 6 min | 192.0.2.224 | RESEARCH-NET | Challenged | User agent issue | BE-120 · no-user-agent |
Identified threats
Clients that tripped a detection rule, newest data first.
| Address ↕ | Country ↕ | Network ↕ | Requests ↕ | Sites ↕ | Detected as ↕ | What it did | Hosts hit | Status | Platform ↕ | User agent ↕ | Actions ↕ | Last seen ↕ | |
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
203.0.113.47 | US | EXAMPLE-NETAS64500 | 2,418 | 3 | Path probing | Requested credential and backup files/.env · /.git/HEAD · /backup.sql | storefront.example api.example | 404 ×2,106 | Chrome Linux · Desktop | Mozilla/5.0 Chrome/145… | BlockedBE-142 | now | |
198.51.100.22 | DE | EDGE-EUAS64501 | 1,904 | 2 | Request flood | Distributed requests across 18 pathsRate rose 14× above the host baseline | portal.example | 200 ×1,421 | Other bot Linux · Bot | AutomationClient/4.2… | ChallengedBE-308 | now | |
192.0.2.81 | GB | CLOUD-DEMOAS64502 | 1,386 | 1 | SQL injection | Injection payloads in query parametersRepeated encoding and identity rotation | api.example | 403 ×1,102 | Chrome Windows · Desktop | Mozilla/5.0 Chrome/151… | BlockedBE-204 | 1 min | |
2001:db8::27 | NL | HOSTING-EUAS64504 | 877 | 4 | Bot spoofing | Claimed a verified crawler identityNetwork ownership did not match | docs.example +3 more | 403 ×844 | Other bot Bot | SearchCrawler/1.0… | BlockedBE-187 | 1 min | |
203.0.113.108 | FR | TRANSIT-EUAS64503 | 721 | 2 | RCE attempt | Shell command payloads in form valuesEncoded command separators and process calls | storefront.example | 403 ×719 | Unknown Script | curl/8.7.1 | BlockedBE-233 | 2 min | |
198.51.100.151 | SG | EDGE-ASIAAS64505 | 612 | 1 | Login abuse | Repeated authentication failures41 usernames across one login endpoint | accounts.example | 401 ×588 | Chrome Mobile Android | Mozilla/5.0 Android 14… | ChallengedBE-165 | 2 min | |
192.0.2.34 | CA | RESEARCH-NETAS64506 | 508 | 5 | No user agent | Automated traffic without client identityHigh request rate across unrelated sites | portal.example +4 more | 404 ×391 | Unknown Script | — | ChallengedBE-120 | 3 min | |
203.0.113.64 | AU | EXAMPLE-APAS64507 | 487 | 1 | File upload | Executable extension in upload requestContent type did not match the filename | storefront.example | 403 ×487 | Firefox Linux · Desktop | Mozilla/5.0 Firefox/146… | BlockedBE-219 | 4 min | |
198.51.100.96 | PL | HOSTING-PLAS64508 | 402 | 2 | 404 sweep | Enumerated 126 missing application pathsAdmin, backup and development path families | api.example docs.example | 404 ×398 | Other bot Bot | ScannerDemo/2.0 | ChallengedBE-173 | 5 min | |
192.0.2.199 | BR | EXAMPLE-BRAS64509 | 366 | 1 | Traversal | Directory traversal sequences in URLEncoded parent directory attempts | portal.example | 403 ×366 | Chrome Windows · Desktop | Mozilla/5.0 Chrome/145… | BlockedBE-227 | 6 min |
Coordinated campaigns
Flagged addresses clustered by network block. Several addresses acting together suggest one operator.
| Network block ↕ | Who owns it | Addresses ↕ | Requests ↕ | Members |
|---|---|---|---|---|
203.0.113.0/28 | EXAMPLE-CDN AS64500 · US | 18 | 8,714 | .2 .3 .5 .7 .8 .9 +12 |
198.51.100.0/27 | EDGE-EU AS64501 · DE | 11 | 4,921 | .4 .6 .11 .14 .18 +6 |
192.0.2.64/27 | CLOUD-DEMO AS64502 · GB | 9 | 3,806 | .65 .68 .71 .75 .81 +4 |
2001:db8:1200::/48 | HOSTING-EU AS64504 · NL | 7 | 2,907 | ::12 ::27 ::42 ::58 +3 |
198.51.100.128/28 | EDGE-ASIA AS64505 · SG | 6 | 1,844 | .129 .132 .137 .141 +2 |
192.0.2.192/28 | EXAMPLE-BR AS64509 · BR | 4 | 978 | .193 .197 .199 .204 |
Group traffic by whatever you need
Sort every column; the same filters as Overview apply.
| Source IP ↕ | Country ↕ | Network ↕ | Requests ↕ | Bytes ↕ | Sites ↕ | Sources ↕ | 2xx ↕ | 3xx ↕ | 4xx ↕ | 5xx ↕ | |
|---|---|---|---|---|---|---|---|---|---|---|---|
203.0.113.47 | US | EXAMPLE-NET | 2,819 | 84 MB | 3 | 1 | 182 | 28 | 2,531 | 78 | |
198.51.100.22 | DE | EDGE-EU | 1,904 | 112 MB | 2 | 1 | 1,421 | 71 | 397 | 15 | |
192.0.2.81 | GB | CLOUD-DEMO | 1,386 | 19 MB | 1 | 1 | 77 | 42 | 1,241 | 26 | |
2001:db8::27 | NL | HOSTING-EU | 877 | 8 MB | 4 | 1 | 22 | 6 | 844 | 5 | |
203.0.113.108 | FR | TRANSIT-EU | 721 | 6 MB | 2 | 1 | 2 | 0 | 719 | 0 | |
198.51.100.151 | SG | EDGE-ASIA | 612 | 27 MB | 1 | 1 | 18 | 4 | 588 | 2 | |
192.0.2.34 | CA | RESEARCH-NET | 508 | 14 MB | 5 | 1 | 83 | 25 | 391 | 9 | |
203.0.113.64 | AU | EXAMPLE-AP | 487 | 51 MB | 1 | 1 | 0 | 0 | 487 | 0 | |
198.51.100.96 | PL | HOSTING-PL | 402 | 3 MB | 2 | 1 | 4 | 0 | 398 | 0 | |
192.0.2.199 | BR | EXAMPLE-BR | 366 | 5 MB | 1 | 1 | 0 | 0 | 366 | 0 |
Every action taken and why
Kept on disk for 30 days. This is the record that survives a restart.
| Time | Address | Network | Action | Reason | Rule | |
|---|---|---|---|---|---|---|
| now | 203.0.113.47 | EXAMPLE-NET US | Blocked | Credential and configuration file probing | BE-142 · credential-file-probe | |
| 1 min | 198.51.100.22 | EDGE-EU DE | Challenged | Distributed request rate exceeded | BE-308 · distributed-request-rate | |
| 2 min | 192.0.2.81 | CLOUD-DEMO GB | Blocked | SQL injection payload in URL | BE-204 · query-sql-injection | |
| 3 min | 198.51.100.29 | EDGE-EU DE | Passed | Browser completed visitor verification | BE-001 · challenge-passed | |
| 4 min | 2001:db8::27 | HOSTING-EU NL | Blocked | Claimed crawler identity did not match network | BE-187 · crawler-spoofing | |
| 6 min | 192.0.2.34 | RESEARCH-NET CA | Challenged | Automated traffic without a user agent | BE-120 · no-user-agent | |
| 9 min | 203.0.113.12 | OFFICE-DEMO GB | Allowlisted | Administrator added office network | manual allowlist | |
| 14 min | 198.51.100.96 | HOSTING-PL PL | Challenged | Enumerated missing application paths | BE-173 · path-probing | |
| 21 min | 203.0.113.108 | TRANSIT-EU FR | Blocked | Remote code execution payload | BE-233 · remote-code-execution | |
| 28 min | 198.51.100.151 | EDGE-ASIA SG | Challenged | Repeated authentication failures | BE-165 · login-failure-rate |
Ports and services
Rules are evaluated in order. The first matching rule decides what happens.
| Order | Label | Action | Protocol | Ports | Sources | Exceptions | Matched | |
|---|---|---|---|---|---|---|---|---|
| 1 | Established trafficKeep existing connections working | Accept | All | All | Established | — | 382,114 | |
| 2 | LoopbackLocal services | Accept | All | All | 127.0.0.0/8 | — | 71,822 | |
| 3 | Web trafficInspected by BashEdge | Accept | TCP | 80,443 | All | Allowlist | 128,604 | |
| 4 | Secure shellAdministrative access | Accept | TCP | 22 | 192.0.2.0/28 | — | 814 | |
| 5 | Mail servicesPublic delivery and submission | Accept | TCP | 25,465,587,993 | All | — | 41,982 | |
| 6 | DNSAuthoritative service | Accept | TCP/UDP | 53 | All | — | 13,721 | |
| 7 | Database public accessNever expose MySQL publicly | Drop | TCP | 3306 | All | 192.0.2.0/28 | 1,205 | |
| 8 | Default inbound policyEverything not explicitly allowed | Drop | All | All | All | — | 8,417 |
Add a rule
Flood protection
Limits how much one address may send to Web ports. Allowlisted addresses and trusted edges are never limited.
| Address | Country | Network | Limit | Packets | Last seen | |
|---|---|---|---|---|---|---|
203.0.113.47 | US | EXAMPLE-NET | Connection rate | 2,841 | now | |
198.51.100.22 | DE | EDGE-EU | Concurrent connections | 1,904 | 1 min | |
192.0.2.81 | GB | CLOUD-DEMO | Broken packets | 1,127 | 2 min | — |
2001:db8::27 | NL | HOSTING-EU | Connection rate | 812 | 3 min | |
203.0.113.108 | FR | TRANSIT-EU | Concurrent connections | 597 | 5 min |
Brute-force protection
Watches server authentication logs and blocks an address that keeps failing to log in.
When to block
| Service | Status | Blocked now | |
|---|---|---|---|
| SSH | Watching | 11 blocked | |
| WHM and cPanel | Watching | 7 blocked | |
| Mail authentication | Watching | 19 blocked | |
| FTP | Watching | 4 blocked | |
| Database | No log | — |
Always allowed
Never challenged or blocked. Reserved ranges and verified crawlers are protected automatically.
| Address | Network | Note | |
|---|---|---|---|
192.0.2.0/28 | OFFICE-DEMO GB | Office network | |
198.51.100.64 | MONITOR-NET DE | External uptime monitor | |
203.0.113.200/30 | BACKUP-NET US | Remote backup service | |
2001:db8:99::/48 | OFFICE-V6 GB | Office IPv6 range | |
198.51.100.88 | PAYMENT-DEMO US | Payment webhook source | |
203.0.113.220 | DEPLOY-NET NL | Deployment runner |
Blocked addresses
Dropped at the firewall before reaching any hosted site.
| When ↕ | Address ↕ | Network ↕ | Rule ↕ | Reason ↕ | Expires ↕ | |
|---|---|---|---|---|---|---|
| now | 203.0.113.47 | EXAMPLE-NET · US | BE-142 | Credential-file probing | 58 minutes | |
| 2 min | 192.0.2.81 | CLOUD-DEMO · GB | BE-204 | SQL injection payload | 1 hour 42 min | |
| 4 min | 2001:db8::27 | HOSTING-EU · NL | BE-187 | Crawler identity spoofing | 3 hours 12 min | |
| 8 min | 203.0.113.108 | TRANSIT-EU · FR | BE-233 | Remote code execution | 5 hours 51 min | |
| 12 min | 203.0.113.64 | EXAMPLE-AP · AU | BE-219 | Executable file upload | 11 hours 48 min | |
| 19 min | 192.0.2.199 | EXAMPLE-BR · BR | BE-227 | Directory traversal | 23 hours 41 min |
Being challenged
Visitors currently required to verify a real browser before continuing.
| When ↕ | Address ↕ | Network ↕ | Rule ↕ | Reason ↕ | Hits ↕ | Expires ↕ | |
|---|---|---|---|---|---|---|---|
| now | 198.51.100.22 | EDGE-EU · DE | BE-308 | Distributed request rate | 1,904 | 12 minutes | |
| 2 min | 198.51.100.151 | EDGE-ASIA · SG | BE-165 | Repeated login failures | 612 | 13 minutes | |
| 3 min | 192.0.2.34 | RESEARCH-NET · CA | BE-120 | No user agent | 508 | 12 minutes | |
| 5 min | 198.51.100.96 | HOSTING-PL · PL | BE-173 | Missing path enumeration | 402 | 25 minutes | |
| 7 min | 203.0.113.39 | TRANSIT-GB · GB | BE-126 | Script-like browser rate | 377 | 8 minutes | |
| 9 min | 2001:db8::91 | EDGE-V6 · US | BE-308 | Distributed request rate | 318 | 6 minutes |
Decide what BashEdge watches, verifies or blocks
Preview likely impact before changing customer traffic.
| Rate limit | Scope | Threshold | Window | Action | Duration | Matches · 24h | |
|---|---|---|---|---|---|---|---|
| Server request ratePer source address | Complete server | 2,400 requests | 1 minute | Verify | 15 minutes | 1,284 | |
| Login endpoint rateAuthentication paths | All domains | 60 requests | 1 minute | Block | 1 hour | 407 | |
| Missing path discoveryHTTP 404 responses | All domains | 120 requests | 5 minutes | Verify | 30 minutes | 291 | |
| Expensive search endpointQuery-heavy application route | shop.example | 45 requests | 1 minute | Verify | 15 minutes | 176 | |
| XML-RPC request rateWordPress XML-RPC | WordPress sites | 30 requests | 1 minute | Block | 6 hours | 39 |
| Country or network | Type | Action | Scope | Requests · 24h | Sources | |
|---|---|---|---|---|---|---|
Example Transit Europe2001:db8:4400::/40 | Network | Verify | All domains | 2,841 | 418 | |
Example Cloud APAC198.51.100.0/24 | Network | Verify | portal.example | 1,308 | 91 | |
Documentation monitoring192.0.2.64/28 | Network | Allow | All domains | 864 | 6 | |
| High-risk anonymous relay regionRegional policy | Country group | Watch | All domains | 731 | 203 | |
Trusted webhook network203.0.113.200/30 | Network | Allow | api.example | 522 | 4 |
| Rule | ID | Action | Addresses · 24h | Requests · 24h | Last matched | |
|---|---|---|---|---|---|---|
| Credential and configuration file probeSecrets, backups and repository files | BE-142 | Block | 37 | 148 | now | |
| No user agentAutomated request without a browser identity | BE-120 | Verify | 54 | 327 | now | |
| SQL injection payloadQuery and request-body injection patterns | BE-204 | Block | 19 | 61 | 2 min | |
| Remote code executionShell, template and command execution patterns | BE-233 | Block | 11 | 32 | 5 min | |
| Crawler identity spoofingBot name does not match verified network ownership | BE-187 | Verify | 26 | 113 | 7 min | |
| Path enumerationRapid requests for missing application paths | BE-173 | Verify | 42 | 891 | 9 min | |
| Directory traversalAttempts to read files outside the Web root | BE-227 | Block | 8 | 21 | 12 min | |
| Suspicious browser request rateBrowser identity combined with script-like timing | BE-126 | Watch | 31 | 83 | 14 min |
| Crawler | Identity check | Verified requests | Spoofed requests | Policy | Last seen | |
|---|---|---|---|---|---|---|
| Googlebot | Forward and reverse DNS | 3,814 | 31 | Allow verified | now | |
| Bingbot | Forward and reverse DNS | 1,906 | 22 | Allow verified | 1 min | |
| Applebot | Published network ownership | 1,241 | 9 | Allow verified | 3 min | |
| Meta external agent | Published network ownership | 1,124 | 18 | Rate limited | now | |
| Uptime monitor | Configured source networks | 897 | 4 | Allow verified | 2 min | |
| Unknown claimed crawler | Ownership could not be verified | 0 | 29 | Block spoofed | 7 min |
ModSecurity findings inside BashEdge
Use existing Web application firewall detections as evidence without giving up BashEdge actions, scope or history.
| Signal | Rule ID | Source | BashEdge action | Addresses · 24h | Requests · 24h | |
|---|---|---|---|---|---|---|
| SQL injection signalDatabase syntax in request input | MS-942100 | ModSecurity | Block | 19 | 61 | |
| Remote execution signalCommand separator and shell payload | MS-932100 | ModSecurity | Block | 11 | 32 | |
| Cross-site scripting signalScript payload in request parameter | MS-941100 | ModSecurity | Verify | 17 | 47 | |
| Protocol anomalyMalformed request headers | MS-920274 | ModSecurity | Watch | 28 | 112 | |
| Restricted file uploadExecutable extension in multipart upload | MS-933110 | ModSecurity | Block | 8 | 19 |
Lockdown Mode
Put the whole server, or only the site under attack, behind visitor verification in one click.
Hosted site controls
Contain one attacked application without changing traffic for every other customer.
| Hosted site | Account | Coverage | Requests · 1h | Lockdown Mode | Emergency Mode | |
|---|---|---|---|---|---|---|
| shop.exampleWordPress and WooCommerce | shopdemo | HTTPS covered | 84,129 | |||
| portal.exampleCustomer account portal | portaldemo | HTTPS covered | 31,822 | |||
| api.exampleApplication API | apidemo | HTTPS covered | 28,704 | |||
| docs.exampleDocumentation site | docsdemo | HTTPS covered | 14,207 | |||
| members.exampleMembership application | memberdemo | HTTPS covered | 12,484 | |||
| status.examplePublic service status | statusdemo | HTTPS covered | 9,177 |
Improvements ranked by real traffic impact
BashEdge turns observed behaviour into practical, reviewable next steps.
Block confirmed credential-file probes
148 matches were challenged and none completed verification. Moving this rule to Block would stop repeat probes sooner.
Based on the last 24 hours · affects 0 verified visitorsAdd a focused rate limit to shop.example
A rotating request campaign repeatedly consumed application workers on one expensive search route.
Suggested threshold: 45 requests per minute per sourceProtect the WordPress login path
Three hosted sites received concentrated authentication traffic from rotating networks.
Suggested scope: /wp-login.php on 3 sitesVerify one untrusted hosting network
91 sources produced repeated missing-path requests and never completed a browser challenge.
Suggested scope: all hosted domains · 1,308 requests observedAllowlist the new uptime monitor
A stable monitoring source is completing visitor verification every five minutes.
Confirm ownership before adding an exceptionAlso considered
No country-wide block suggested.Traffic is distributed and legitimate visitors share the same regions.
No complete-server lockdown suggested.The current load is contained by targeted rules.
No verified crawler block suggested.Known crawler networks are passing ownership checks.
Protection defaults for this server
Keep automatic decisions predictable across every hosted account.
/usr/local/apache/domlogsPanel discovery486 hosted domains currently discovered.SSH · panel · mail · FTPAutomatic discoveryFour active services are being watched./var/lib/bashedgeInstallationNever sent to this public demonstration.Stored on the protected serverThe values shown here are synthetic demo settings. A real BashEdge installation keeps configuration and traffic evidence locally.