v2.0 · Production · GA

Mcaster1BackDraft

The AI Web Application Firewall that doesn’t just block bots — it eliminates them. Real-time inspection, kernel-level auto-ban, deception honeypots, and automated abuse-reporting in a single C++17 binary. FastCGI-native. No edge dependency, no SaaS phone-home. Protecting 30+ production domains today.

Pricing & Licensing Book a Demo
Production, active-enforcement. BackDraft is the live WAF for the entire Mcaster1 / CasterClub / Audiorealm fleet — inspecting, scoring, and actively banning threats in real time. Proprietary, licensed software: we install, tune, and manage it on your infrastructure. Not downloadable, not open-source.

“BackDraft will suck the life out of you and your botnet, turning it into a notnet :)”

Single Binary. Zero Sidecars.

BackDraft runs as one hardened C++17 daemon alongside your existing nginx and PHP-FPM — no Go sidecar, no Lua hot-patching, no external edge dependency and no SaaS phone-home. Inspection, scoring, enforcement, and the admin console all live in one process on your own box.

Active Defense & Fight-Back

Most WAFs stop at “403 Forbidden.” BackDraft turns an attack into a dead end, a fingerprint, and a filed complaint.

NEW

Tripwire → Kernel Auto-Ban

Any request to a path no legitimate user hits (config.php~, .env, wp-login.php, .git) drops the source IP at the kernel firewall in milliseconds — every subsequent packet black-holed. Scales to a botnet flood; whitelist-protected so you never ban yourself.

NEW

Deception Honeypot

Scanners asking for your config backup get a decoy stuffed with canary credentials — the bot “wins” while it’s fingerprinted and banned. Use the canaries anywhere and you’ve just told us your next move.

NEW

Poison Cookies

Tripped bots are tagged with a taint cookie. Rotate IPs all you want — carry the cookie and you’re re-banned on sight.

NEW

whois Forensics

Every ban is enriched with a live whois: owner, netblock CIDR, country, and the RIR abuse contact — recon and evidence, automatically.

NEW

Auto Abuse-Reporting

BackDraft composes an evidence-backed abuse report, parses the RIR abuse desk from whois, dedupes per-netblock, and files it — turning your attacker’s host against them.

NEW

Proxy / VPN Awareness

Passive detection of proxy headers and header-inconsistent clients — logged, never blocked. Full visibility for security intel and for troubleshooting legitimate VPN users.

NEW

WebGL Trust Seal

A VeriSign-style “Protected by BackDraft” seal for your footer. Visitors click to verify their own challenge status and see live browser/security info — trust, rendered in WebGL.

BotProof PoW Turnstile

WebGL proof-of-work challenge for suspicious sessions — solve once, pass for the session. No reCAPTCHA, no Google JS phone-home.

IC3 Redirect

Confirmed secret-probes are permanently redirected to the FBI Internet Crime Complaint Center. A small gift for the persistent.

WAF Rule Engine

Nine production rule classes, continuously tuned against live fleet traffic.

SQL Injection (basic + advanced)
XSS — reflected and stored
Path Traversal
Command Injection
RFI / LFI
Bot User-Agent
Rate Limiting
IP Blocklist (geo + kernel-level)
Request Pattern Anomaly

Platform Features

The engine behind the defense.

Pure C++17, Single Binary

One executable, one systemd unit. No Go sidecar, no Lua module, no Node shim. Hardware-aware thread pool for inspection at line rate.

Native FastCGI Integration

BackDraft speaks FastCGI directly to PHP-FPM after inspection — a straightforward, debuggable request flow with no extra hop.

Learning → Enforce

Onboard in inspect-and-log mode to baseline your traffic, then flip to active enforcement per-site once the false-positive rate is proven — we tune it with you.

ClamAV Upload Scanning

File uploads scanned inline with ClamAV before reaching PHP. Malware, EICAR, and suspicious binaries rejected at the WAF layer.

Real-Time Dashboard

Chart.js analytics in a dark cybersecurity theme: threat timeline, top-blocked rules, geo heat-map, per-site volume, suspicious-UA ranking, live ban feed.

MariaDB-Backed

Threats, sessions, rule hits, bans, and audit events persist to MariaDB — prepared statements only, cross-site reputation sharing across your fleet.

SOC2-Friendly Audit Log

HMAC-chained audit log on rule changes, user actions, and IP-block adjustments. Tamper-evident, append-only, per-record signatures.

Secure Lock OTP

Email-OTP challenge for sensitive paths (admin, billing). Configurable per site, per path, per role.

Pricing & Licensing

Proprietary, licensed, and fully managed — we install, configure, and tune BackDraft on your infrastructure. No downloads, no DIY.

Monthly — Pay As You Grow

$25/mo flat
  • + $15 / protected page / month
  • Full active-defense suite
  • Custom install & setup included
  • Managed rule tuning & updates
  • Real-time dashboard & API
  • Scale pages up or down anytime
Start Monthly

Fleet / Custom

Let’s talk
  • Multi-site & multi-tenant volume
  • Air-gapped / regulated deployments
  • White-label trust seal
  • Dedicated onboarding & SLA
  • Cross-site reputation sharing
Get a Quote

Capabilities at a Glance

A high-level overview. Exact configuration, rule sets, hardening, and deployment topology are tailored per license and client engagement.

Compiled, On-Prem Core

A hardened, compiled daemon that runs on your own infrastructure — no edge dependency, no SaaS phone-home.

AI WAF + Active Defense

Real-time inspection and scoring with kernel-level enforcement, deception honeypots, and automated fight-back.

Threat Intelligence

Database-backed threat, session, and ban history with cross-site reputation sharing across your fleet.

Malware Scanning

Inline upload scanning rejects malicious files before they reach your application.

Tamper-Evident Audit

Cryptographically chained, append-only audit trail suitable for SOC2 / ISO 27001 evidence.

Managed Install & Tuning

We scope, deploy, and tune BackDraft with you — configured to your sites, not a one-size-fits-all box.

Who It’s For

Three audiences this was built for.

Single-Operator Hosters

You run nginx for your own and a few client sites. Cloudflare WAF costs more than your hosting. BackDraft is one licensed binary on the same box — no edge dependency, no DNS migration.

Multi-Tenant PHP Shops

Per-site rule sets, dashboards, and challenge toggles. FastCGI-native, so you keep PHP-FPM and don’t bolt on a separate proxy layer. Bill it back per site or per page.

Air-Gapped & Regulated

No SaaS phone-home. No external CAPTCHA service. ClamAV scans locally. Audit log is HMAC-chained and exportable for SOC2 / ISO 27001 evidence.

Ready to turn your botnet problem into a notnet?

We’ll scope your sites, install BackDraft, and tune it with you — typically live within a day.

Request a License Book a Demo