Emergency server help: get in touch

Install Imunify360 DirectAdmin: ImunifyAV Setup

How to install Imunify360 or the free ImunifyAV scanner on a DirectAdmin server, the ModSecurity and CSF prerequisites that decide whether the WAF and firewall components work, and how to confirm the agent, plugin and scans are running.

Published Updated 6 min read

Imunify360 is the commercial security suite from the CloudLinux team: a firewall with a shared reputation database, a ModSecurity-based WAF with vendor-managed rules, malware scanning and cleanup, and proactive defence for PHP. ImunifyAV is the free malware scanner from the same family, with a paid ImunifyAV+ tier that adds cleanup. Both integrate with DirectAdmin through a plugin that appears at Admin Level and, for Imunify360, in the user interface. The 2025–2026 releases added AlmaLinux 10 (September 2025) and Debian 13 (December 2025) support, so every OS DirectAdmin currently ships on is covered.

Short answer: Update DirectAdmin and CustomBuild, build ModSecurity (./build set modsecurity yes && ./build modsecurity) if you want the WAF, decide whether CSF stays, then run bash i360deploy.sh --key YOUR_LICENSE_KEY for Imunify360 or bash imav-deploy.sh for the free ImunifyAV scanner. The installer adds the agent and the DirectAdmin plugin in ten to twenty minutes without a reboot. Confirm it with imunify360-agent rstatus, start a first scan of /home, and keep Proactive Defense in LOG mode and cleanup set to quarantine for the first weeks.

Prerequisites

The installer is picky about the state it finds. Before running it:

  • Update the panel and CustomBuild: da update followed by ./build update in /usr/local/directadmin/custombuild.
  • Enable ModSecurity if you want the Imunify360 WAF. Imunify installs its own ruleset and takes over management of ModSecurity, but it needs the engine present: ./build set modsecurity yes and ./build modsecurity. The modsecurity_ruleset option becomes irrelevant afterwards because Imunify replaces it.
  • Decide what happens to CSF. Imunify360 has its own firewall and works alongside CSF, but two daemons managing the same iptables chains is the classic cause of “rules disappear after a restart”. The installer detects CSF and integrates with it; if you would rather have one firewall, uninstall CSF first with ./build set csf no and csf -x, then remove it. CloudLinux has published a migration tool from ConfigServer to Imunify360 since ConfigServer’s closure; on DirectAdmin the simpler path is the clean uninstall.
  • Have the license key from the Imunify portal, or use IP-based licensing if the server IP is registered there.

Installing Imunify360

cd /root
wget https://repo.imunify360.cloudlinux.com/defence360/i360deploy.sh
bash i360deploy.sh --key YOUR_LICENSE_KEY

Omit --key for an IP-based license. The script installs the agent packages from the Imunify repository, the DirectAdmin plugin, and, when ModSecurity is present, the WAF rules. It takes ten to twenty minutes. Reboot is not required. The plugin appears as Imunify360 under Admin Level in the Evolution skin, and users get their own page showing malware findings for their files.

Installing ImunifyAV

For the free scanner only:

cd /root
wget https://repo.imunify360.cloudlinux.com/defence360/imav-deploy.sh
bash imav-deploy.sh

No key is needed. ImunifyAV scans on a schedule and reports; cleanup requires an ImunifyAV+ license, which can be added later from the same interface without reinstalling. ImunifyAV does not include the firewall or WAF, so keep CSF and CustomBuild’s ModSecurity ruleset in place.

First configuration

Most administration happens in the plugin, but the CLI is faster for a few things. Check the agent, run an initial scan and review the default policy:

imunify360-agent version
imunify360-agent rstatus
imunify360-agent malware on-demand start --path /home
imunify360-agent config show | head -n 60

Three settings deserve a decision on day one. Proactive Defense (PHP-level exploit blocking) should be in LOG mode for a week before switching to KILL, because it flags some legitimate obfuscated plugins. WebShield, the reverse proxy that presents captcha challenges, changes what the web server sees as the client IP; on DirectAdmin it inserts itself in front of Apache or LiteSpeed and you must ensure your logs and any rate limiting read the forwarded header.

The Under Attack Mode added in August 2026 and the layer-7 rate limiter are worth enabling on servers that see regular application-layer floods. And the WAF for WordPress rules, on by default since the end of August 2026, add WordPress-specific protection that overlaps with the general ruleset; leave them on unless a specific site breaks.

Malware cleanup defaults to quarantine rather than delete. Keep it that way for the first month so a false positive can be restored from the plugin.

Common pitfall: the plugin loads but the WAF is inactive

The most frequent post-install complaint is that the interface shows the WAF as disabled or “ModSecurity not detected”. This happens when ModSecurity was not built before the installer ran, or when the web server was switched after installation. Build ModSecurity, then let Imunify reconfigure:

cd /usr/local/directadmin/custombuild && ./build modsecurity && ./build rewrite_confs
imunify360-agent features install ModSecurity
imunify360-agent rstatus

A related issue on OpenLiteSpeed and LiteSpeed Enterprise: Imunify supports both, but the WAF rules are loaded through the LiteSpeed-style configuration, so ./build rewrite_confs after any LiteSpeed change is what makes them active again.

Verify

Confirm the agent is registered and the components are up:

imunify360-agent rstatus
imunify360-agent list
imunify360-agent malware history list --limit 5
systemctl status imunify360 --no-pager

For Imunify360, test the WAF with a request that should be blocked, such as a query string containing an obvious SQL injection payload, and check that the plugin’s incidents page records it. Drop a harmless EICAR test file into a user’s public_html and confirm the next scan reports and quarantines it. Finally, make sure CSF (if kept) and Imunify are not fighting: csf -ra followed by imunify360-agent rstatus should leave both reporting healthy, and iptables -L -n | head should show Imunify’s chains still present after the CSF restart. If you removed CSF, re-check the server security audit output, since Imunify’s firewall does not cover the port-exposure checks that CSF handled.

Install Imunify360 DirectAdmin at a glance

Install Imunify360 DirectAdmin summary card: Update DirectAdmin and CustomBuild, build ModSecurity (./build set modsecurity yes && ./build modsecurity) if you want…
In short: Update DirectAdmin and CustomBuild, build ModSecurity (./build set modsecurity yes && ./build modsecurity) if you want the WAF, decide whether CSF stays, then run bash i360deploy.sh –key YOUR_LICENSE_KEY for Imunify360 or bash…

Official documentation: Imunify360 documentation, DirectAdmin documentation, Linux man pages.

Related guides: Exim, Dovecot or DirectAdmin still serving the old certificate after renewal · KernelCare on cPanel and DirectAdmin servers: setup, verification and rollback · Enabling ModSecurity with OWASP CRS or Comodo rules on DirectAdmin and managing per-domain exclusions.

Frequently asked questions

Can Imunify360 run alongside CSF on DirectAdmin?

Yes, the installer detects CSF and integrates with it, but two daemons managing the same iptables chains is the usual cause of rules vanishing after a restart. If you want a single firewall, remove CSF cleanly with ./build set csf no and csf -x before installing, and keep the security audit script for the port checks CSF used to do.

What is the difference between ImunifyAV and Imunify360?

ImunifyAV is the free malware scanner that detects and reports; ImunifyAV+ adds cleanup for a fee. Imunify360 is the full suite with the reputation firewall, ModSecurity WAF, Proactive Defense for PHP, WebShield and malware cleanup. ImunifyAV can be upgraded from the same interface without reinstalling.

Why does Imunify360 say ModSecurity is not detected on DirectAdmin?

The WAF needs the ModSecurity engine built by CustomBuild before the installer runs, and a web-server switch afterwards can break the integration. Run ./build modsecurity && ./build rewrite_confs, then imunify360-agent features install ModSecurity, and check imunify360-agent rstatus.

Free website test

Is your website set up right?

Check SSL, security headers, redirects, robots.txt, sitemap, llms.txt and security.txt in one test. It takes about 30 seconds.