Imunify360 vs. ImunifyAV: What is the difference?

Picture of Silvio Mazenauer
Silvio Mazenauer
ImunifyAV detects malware, Imunify360 goes significantly further: real-time scanning, firewall, Proactive Defense, and automatic cleanup protect websites on multiple levels. We explain the differences and show how the protection works at CURIAWEB.
Imunify360 and ImunifyAV – Malware Protection and Server Security at CURIAWEB

Websites are constantly threatened by automated bots, malware, compromised scripts, and other attacks. An attack does not necessarily have to be targeted at a specific website. A large portion runs fully automatically: bots scan servers and websites for known vulnerabilities, outdated plugins, insecure access credentials, or opportunities to inject malicious code.

This is precisely where to start ImunifyAV and Imunify360 Both security solutions are from CloudLinux and were developed specifically for Linux web servers and hosting environments. Although the names sound similar, the two solutions differ significantly in their range of functions.

Simply put, ImunifyAV a malware scanner. Imunify360 goes significantly further, forming a multi-layered security platform that detects and cleans malware, blocks attacks, analyzes suspicious behavior, and can protect websites even while an attack is underway.

What is ImunifyAV?

ImunifyAV is a security solution for detecting malware on Linux web servers. The scanner examines files within a hosting environment while attempting to detect malicious or tampered code.

These can include smuggled PHP files, backdoors, webshells, or manipulated components of a website. Especially with content management systems like WordPress, attackers can modify existing files or place additional files in the web space after a successful compromise.

A typical example is a vulnerable WordPress plugin. If an attacker succeeds in injecting malicious code through this vulnerability, the malware scanner can detect the suspicious file.

How does the malware scanner work?

The scanner scans files and analyzes them for known and suspicious structures. It doesn't just search for specific file names. Malware can hide in regular PHP files, manipulate existing code, or be heavily obfuscated.

Imunify therefore uses various detection mechanisms to track down malware, backdoors, webshells, and other manipulations.

This is an important component of server security. However, there is a fundamental difference between the Detecting an infection and the actively preventing an attack.

Right at this point, the significantly broader range of features of Imunify360 begins.

What is Imunify360?

Imunify360 is a comprehensive security platform for Linux web servers. The malware scanner is just one of several layers of protection.

The system combines malware detection and automatic cleanup with a firewall, web application firewall, intrusion detection and prevention, proactive defense, brute-force protection, and mechanisms against malicious bots and automated attacks.

The crucial difference thus lies in the approach: A malware scanner searches for malicious software. Imunify360 additionally attempts to detect and stop many attacks before they result in a successful compromise of the website.

Real-time protection: Files are not just checked during the next scan

A particularly important function of Imunify360 is the Real-Time Malware Scan. This real-time monitoring is activated in CURIAWEB.

This means that protection does not exclusively wait for a scheduled malware scan. Imunify360 can monitor changes to files in a website's DocumentRoot and immediately check newly or newly modified files.

Even files uploaded via a website or HTTP/HTTPS can be scanned in real time. The same applies to uploads via FTP, provided the server is configured accordingly.

This is relevant, for example, when a compromised web application attempts to place a malicious PHP file on the web space or when malware is to be introduced via an upload function. Imunify360 can detect such a file immediately and trigger appropriate protective measures instead of encountering it hours later during the next full scan.

This significantly reduces the time window between the appearance of a malicious file and its detection.

Detect malware and clean it automatically

If Imunify360 finds malware, protection doesn't end with a simple warning. The platform can automatically clean infected files.

This is particularly important in hosting environments. A compromised website can damage more than just the actual operator. Injected code can be misused, for example, for sending spam, phishing, unwanted redirects, spying on login credentials, or launching further attacks.

The faster an infection is detected and eliminated, the smaller the risk of further problems developing from it.

What does the Web Application Firewall do?

A Web Application Firewall, WAF for short, analyzes web requests and attempts to detect malicious requests before the targeted application processes them.

This is particularly relevant for WordPress. A WordPress website often consists not only of WordPress itself, but also of numerous plugins and themes. If a security vulnerability is discovered in a popular extension, automated systems sometimes start scanning the internet for vulnerable installations within a short time.

The WAF can detect and block corresponding attack patterns. Imunify360 also supports so-called Virtual Patching. This makes it possible to protect known vulnerabilities in WordPress, plugins, and themes without having to modify the file in question.

This does not replace a necessary update. However, it can form an important additional layer of protection, especially in the period between a security vulnerability becoming known and the installation of the corresponding update.

We explain in more detail why regular updates remain important anyway in the article Why WordPress updates are necessary.

Proactive Defense protects during execution

Proactive Defense pursues yet another approach.

A classical malware scanner examines files and attempts to determine whether malicious code is present in them. Proactive Defense, on the other hand, analyzes the Behavior of PHP scripts during their execution.

This enables the system to detect suspicious actions, such as obfuscated command executions, the injection of malicious code, certain forms of SQL injection, or an attempt by a manipulated script to send spam.

This is particularly interesting in the case of new or yet unknown attack methods. Instead of exclusively searching for a known malware signature, consideration is also given to what a PHP script is actually trying to execute.

Upon proper detection, Imunify360 can stop the execution of the malicious process.

Intrusion Detection and Protection against Brute-Force Attacks

Not every attack consists of a malicious file. A classic example is automated login attempts.

Bots can try out large numbers of different combinations of usernames and passwords in a short time. Such brute-force attacks can affect various services on a server.

Imunify360 monitors suspicious activity and can automatically block conspicuous IP addresses or subject them to additional verification. This layer of protection thus operates independently of whether malware is already present on a website.

Protection against bots and automated attacks

A significant portion of today's internet traffic is generated by automated systems. Among them are legitimate search engine crawlers, as well as scanners, scrapers, spam bots, and automated attack tools.

Imunify360 can detect suspicious automated traffic and intercept corresponding access requests. In doing so, legitimate visitors should remain as unaffected as possible.

This not only protects against certain attacks, but can also conserve server resources. A malicious bot whose request is already stopped at an upstream security layer cannot trigger resource-intensive processes within a website.

Additional protection directly in WordPress

With WordPress, CURIAWEB goes a step further. The Imunify Security Plugin for WordPress is automatically installed and works together with the server-side Imunify360 protection.

Therefore, the customer does not need to search for, purchase, or manually install the security plugin themselves.

The plugin brings information from the server-side security platform directly into the WordPress administration area. Among other things, the current security status of the website can be viewed there. Detected or cleaned malware as well as the status of important protection functions can thus be made visible directly within WordPress.

At the same time, the plugin complements the server-side protection mechanisms with WordPress-specific functions. This includes, in particular, the Web Application Firewall with virtual patching for known vulnerabilities in WordPress core, plugins, and themes.

Another layer of protection involves automated bots. The protection can detect and limit aggressive crawlers, scrapers, and other automated access before WordPress even needs to be fully loaded.

With this, a WordPress website at CURIAWEB multiple layers intertwined: server-side protection by Imunify360 and additional WordPress-specific protection directly within the CMS.

ImunifyAV or Imunify360 – what is the actual difference?

The most important difference is not that one of the products simply has a slightly better virus scanner.

ImunifyAV focuses primarily on malware detection. It primarily answers the question: Are there suspicious or malicious files on the server?

Imunify360, on the other hand, takes a multi-layered security approach. Malware detection is combined with automatic remediation, real-time monitoring, firewall mechanisms, attack detection, proactive defense, and further layers of protection.

FunctionImunifyAVImunify360
Malware scannerYesYes
Malware detectionYesYes
Automatic malware removalNot part of the free basic versionYes
Real-time file monitoringLimited or product-dependentYes
Web Application FirewallProtection function not fully activeYes
Virtual Patching for WordPressMonitoringActive protection
Proactive DefenseNoYes
Intrusion Detection / PreventionNoYes
Advanced bot and attack protectionRestrictedYes

Why multiple security layers are important

No single security measure can completely protect a website.

A malware scanner can detect malicious software, but it cannot prevent every security vulnerability. A firewall can block many attacks, but it does not replace software updates. Secure passwords protect user accounts, but they do not help against an unpatched vulnerability in a plugin.

Therefore, a multi-layered approach makes sense.

At CURIAWEB, in addition to Imunify360, other security mechanisms are used. For example, hosting accounts run in isolated CloudLinux LVE environments. This separates customer accounts from one another and controls resources.

You can find out more about the technical hosting environment at Swiss web hosting by CURIAWEB.

Imunify360 is fully included at CURIAWEB

At CURIAWEB has Imunify360 with its protection features activated for all hosting customers and included in hosting at no extra charge.

Dazu gehören unter anderem Malware-Scanning und automatische Bereinigung, Echtzeitüberwachung, Web Application Firewall, Proactive Defense, Intrusion Detection und Prevention sowie der Schutz vor verschiedenen automatisierten Angriffen.

Auch der Echtzeit-Scan ist aktiviert. Neue und veränderte Dateien werden dadurch nicht einfach bis zum nächsten regulären Malware-Scan ignoriert. Uploads und Dateiänderungen können unmittelbar vom Sicherheitssystem überprüft werden.

WordPress-Installationen erhalten zusätzlich automatisch das Imunify Security Plugin. Dadurch wird der serverseitige Schutz um WordPress-spezifische Sicherheitsfunktionen ergänzt und der Sicherheitsstatus direkt in WordPress sichtbar.

Für den Kunden bedeutet das: Es muss keine separate Imunify360-Lizenz gekauft und keine zusätzliche Security-Lösung eingerichtet werden, um diese Schutzmechanismen zu nutzen.

Gerade für WordPress ist das relevant. Aufgrund seiner enormen Verbreitung ist WordPress ein häufiges Ziel automatisierter Angriffe. Wer sich nicht selbst um Updates und die technische Wartung kümmern möchte, findet mit Managed WordPress eine zusätzliche Möglichkeit, die laufende Wartung der Installation abzugeben.

Sicherheit ersetzt keine Backups

Auch ein umfangreiches Sicherheitssystem wie Imunify360 macht Backups nicht überflüssig.

Ein Backup verfolgt ein anderes Ziel. Sicherheitssoftware versucht Angriffe zu verhindern, verdächtiges Verhalten zu erkennen und Malware zu beseitigen. Ein Backup ermöglicht dagegen die Wiederherstellung von Daten nach einem technischen Fehler, einer versehentlichen Änderung, einem fehlgeschlagenen Update oder einer Beschädigung.

Bei CURIAWEB werden Kundendaten deshalb zusätzlich täglich gesichert und 30 Backup-Stände rollierend aufbewahrt.

Wie diese Sicherungen funktionieren, erklären wir in der Knowledge Base unter Tägliche Backups bei CURIAWEB. Die Wiederherstellung eines vorhandenen Backup-Stands kann bei Bedarf über den Support angefordert werden.

Sicherheit und Datensicherung sind deshalb keine Alternativen. Sie erfüllen unterschiedliche Aufgaben und ergänzen sich.

Imunify360 ersetzt trotzdem keine sichere Website

Bei all diesen Schutzmechanismen sollte eines nicht missverstanden werden: Auch Imunify360 ist kein Freipass, WordPress, Plugins oder Themes jahrelang nicht zu aktualisieren.

Sicherheitsupdates sollten weiterhin zeitnah installiert, nicht mehr benötigte Erweiterungen entfernt und starke, individuelle Passwörter verwendet werden. Eine zusätzliche serverseitige Sicherheitsplattform reduziert Risiken erheblich, beseitigt aber nicht die Verantwortung für eine sauber gepflegte Website.

Wer wissen möchte, was nach einem erfolgreichen Angriff tatsächlich passiert und welche Schritte dann notwendig sind, findet dazu unseren ausführlichen Artikel WordPress hacked – what now? Immediate action & recovery.

Fazit: ImunifyAV erkennt Malware – Imunify360 schützt auf mehreren Ebenen

ImunifyAV und Imunify360 verfolgen dasselbe grundlegende Ziel, unterscheiden sich aber deutlich beim Umfang.

ImunifyAV ist in erster Linie ein Malware-Scanner. Er hilft dabei, schädliche oder manipulierte Dateien auf einem Webserver zu erkennen.

Imunify360 erweitert diesen Ansatz zu einer umfassenden Sicherheitsplattform. Malware-Scanning und automatische Bereinigung werden mit Echtzeitüberwachung, Firewall-Mechanismen, Angriffserkennung, Proactive Defense, WordPress-spezifischem Schutz und weiteren Sicherheitsebenen kombiniert.

Bei CURIAWEB sind diese Schutzmechanismen Bestandteil des Webhostings. Imunify360 ist für alle Hosting-Kunden aktiviert, der Echtzeitschutz läuft serverseitig und WordPress-Installationen werden zusätzlich automatisch mit dem Imunify Security Plugin abgesichert – ohne zusätzliche Lizenzkosten für den Kunden.

Share this post:

You might also be interested in this

Cookie Consent with Real Cookie Banner