One thing that occurred to me that is SORELY missing from WHM is mod_security cluster management! This would be a great opportunity for Comodo to one-up cPanel and have your WHM plugin handle modsecurity clustering/management. Because you already have automatic updating built into your plugin, the next phase would be modsecurity cluster management which could be easily done via WAF-FLE!! Great project which you guys could throw your resources behind to beef up and turn it into a WHM plugin…
This is one of those “must haves” for multi-server hosting environments.
Features:
WAF-FLE is a OpenSource ModSecurity Console, allows modsecurity admin to store, view and search events sent by sensors using a graphical dashboard to drill-down and find quickly the most relevant events. It is designed to be fast and flexible, while keeping a powerful and easy to use filter, with almost all fields clickable to use on filter.
WAF-FLE Features
- Central event console
- Support Modsecurity in “traditional” and “Anomaly Scoring”
- Brings mlog2waffle as a replacement to mlogc
- Receive events using mlog2waffle or mlogcmlog2waffle: in real-time, following log tail, or batch scheduled in crontabmlogc: in real-time, piped with ModSecurity log, in batch scheduled in crontab
- No sensor limit
- Drill down of events with filter
- Dashboard with recent events information
- Almost every event data and charts are “clickable” deepening the drill down filter
- Inverted filter (to filter for “all but this item”)
- Filter for network (in CIDR format, x.x.x.x/22)
- Original format (Raw) to event download
- Use Mysql as database
- Wizard to help configure log feed between ModSecurity sensors and WAF-FLE
- Open Source released under GPL v2