Mcaster1BackDraft
The AI Web Application Firewall that doesn’t just block bots — it eliminates them. Real-time inspection, kernel-level auto-ban, deception honeypots, and automated abuse-reporting in a single C++17 binary. FastCGI-native. No edge dependency, no SaaS phone-home. Protecting 30+ production domains today.
“BackDraft will suck the life out of you and your botnet, turning it into a notnet :)”
Single Binary. Zero Sidecars.
BackDraft runs as one hardened C++17 daemon alongside your existing nginx and PHP-FPM — no Go sidecar, no Lua hot-patching, no external edge dependency and no SaaS phone-home. Inspection, scoring, enforcement, and the admin console all live in one process on your own box.
Active Defense & Fight-Back
Most WAFs stop at “403 Forbidden.” BackDraft turns an attack into a dead end, a fingerprint, and a filed complaint.
Tripwire → Kernel Auto-Ban
Any request to a path no legitimate user hits (config.php~, .env, wp-login.php, .git) drops the source IP at the kernel firewall in milliseconds — every subsequent packet black-holed. Scales to a botnet flood; whitelist-protected so you never ban yourself.
Deception Honeypot
Scanners asking for your config backup get a decoy stuffed with canary credentials — the bot “wins” while it’s fingerprinted and banned. Use the canaries anywhere and you’ve just told us your next move.
Poison Cookies
Tripped bots are tagged with a taint cookie. Rotate IPs all you want — carry the cookie and you’re re-banned on sight.
whois Forensics
Every ban is enriched with a live whois: owner, netblock CIDR, country, and the RIR abuse contact — recon and evidence, automatically.
Auto Abuse-Reporting
BackDraft composes an evidence-backed abuse report, parses the RIR abuse desk from whois, dedupes per-netblock, and files it — turning your attacker’s host against them.
Proxy / VPN Awareness
Passive detection of proxy headers and header-inconsistent clients — logged, never blocked. Full visibility for security intel and for troubleshooting legitimate VPN users.
WebGL Trust Seal
A VeriSign-style “Protected by BackDraft” seal for your footer. Visitors click to verify their own challenge status and see live browser/security info — trust, rendered in WebGL.
BotProof PoW Turnstile
WebGL proof-of-work challenge for suspicious sessions — solve once, pass for the session. No reCAPTCHA, no Google JS phone-home.
IC3 Redirect
Confirmed secret-probes are permanently redirected to the FBI Internet Crime Complaint Center. A small gift for the persistent.
WAF Rule Engine
Nine production rule classes, continuously tuned against live fleet traffic.
Platform Features
The engine behind the defense.
Pure C++17, Single Binary
One executable, one systemd unit. No Go sidecar, no Lua module, no Node shim. Hardware-aware thread pool for inspection at line rate.
Native FastCGI Integration
BackDraft speaks FastCGI directly to PHP-FPM after inspection — a straightforward, debuggable request flow with no extra hop.
Learning → Enforce
Onboard in inspect-and-log mode to baseline your traffic, then flip to active enforcement per-site once the false-positive rate is proven — we tune it with you.
ClamAV Upload Scanning
File uploads scanned inline with ClamAV before reaching PHP. Malware, EICAR, and suspicious binaries rejected at the WAF layer.
Real-Time Dashboard
Chart.js analytics in a dark cybersecurity theme: threat timeline, top-blocked rules, geo heat-map, per-site volume, suspicious-UA ranking, live ban feed.
MariaDB-Backed
Threats, sessions, rule hits, bans, and audit events persist to MariaDB — prepared statements only, cross-site reputation sharing across your fleet.
SOC2-Friendly Audit Log
HMAC-chained audit log on rule changes, user actions, and IP-block adjustments. Tamper-evident, append-only, per-record signatures.
Secure Lock OTP
Email-OTP challenge for sensitive paths (admin, billing). Configurable per site, per path, per role.
Pricing & Licensing
Proprietary, licensed, and fully managed — we install, configure, and tune BackDraft on your infrastructure. No downloads, no DIY.
Annual — Per Site
- Unlimited protected pages
- Full active-defense suite
- Custom install & setup included
- Managed rule tuning & updates
- Real-time dashboard & API
- Auto abuse-reporting + forensics
Monthly — Pay As You Grow
- + $15 / protected page / month
- Full active-defense suite
- Custom install & setup included
- Managed rule tuning & updates
- Real-time dashboard & API
- Scale pages up or down anytime
Fleet / Custom
- Multi-site & multi-tenant volume
- Air-gapped / regulated deployments
- White-label trust seal
- Dedicated onboarding & SLA
- Cross-site reputation sharing
Capabilities at a Glance
A high-level overview. Exact configuration, rule sets, hardening, and deployment topology are tailored per license and client engagement.
Compiled, On-Prem Core
A hardened, compiled daemon that runs on your own infrastructure — no edge dependency, no SaaS phone-home.
AI WAF + Active Defense
Real-time inspection and scoring with kernel-level enforcement, deception honeypots, and automated fight-back.
Threat Intelligence
Database-backed threat, session, and ban history with cross-site reputation sharing across your fleet.
Malware Scanning
Inline upload scanning rejects malicious files before they reach your application.
Tamper-Evident Audit
Cryptographically chained, append-only audit trail suitable for SOC2 / ISO 27001 evidence.
Managed Install & Tuning
We scope, deploy, and tune BackDraft with you — configured to your sites, not a one-size-fits-all box.
Who It’s For
Three audiences this was built for.
Single-Operator Hosters
You run nginx for your own and a few client sites. Cloudflare WAF costs more than your hosting. BackDraft is one licensed binary on the same box — no edge dependency, no DNS migration.
Multi-Tenant PHP Shops
Per-site rule sets, dashboards, and challenge toggles. FastCGI-native, so you keep PHP-FPM and don’t bolt on a separate proxy layer. Bill it back per site or per page.
Air-Gapped & Regulated
No SaaS phone-home. No external CAPTCHA service. ClamAV scans locally. Audit log is HMAC-chained and exportable for SOC2 / ISO 27001 evidence.
Ready to turn your botnet problem into a notnet?
We’ll scope your sites, install BackDraft, and tune it with you — typically live within a day.
Request a License Book a Demo