# Install Imunify360 DirectAdmin: ImunifyAV Setup

Source: https://srvscripts.com/guides/install-imunify360-directadmin/
Updated: 2026-10-03
Publisher: srvScripts (https://srvscripts.com/)

Imunify360 is the commercial security suite from the CloudLinux team: a firewall with a shared reputation database, a ModSecurity-based WAF with vendor-managed rules, malware scanning and cleanup, and proactive defence for PHP. ImunifyAV is the free malware scanner from the same family, with a paid ImunifyAV+ tier that adds cleanup. Both integrate with DirectAdmin through a plugin that appears at Admin Level and, for Imunify360, in the user interface. The 2025–2026 releases added AlmaLinux 10 (September 2025) and Debian 13 (December 2025) support, so every OS DirectAdmin currently ships on is covered.

In short: Update DirectAdmin and CustomBuild, build ModSecurity (./build set modsecurity yes && ./build modsecurity) if you want the WAF, decide whether CSF stays, then run bash i360deploy.sh –key YOUR_LICENSE_KEY for Imunify360 or bash…

**Short answer:** Update DirectAdmin and CustomBuild, build ModSecurity (`./build set modsecurity yes && ./build modsecurity`) if you want the WAF, decide whether CSF stays, then run `bash i360deploy.sh --key YOUR_LICENSE_KEY` for Imunify360 or `bash imav-deploy.sh` for the free ImunifyAV scanner. The installer adds the agent and the DirectAdmin plugin in ten to twenty minutes without a reboot. Confirm it with `imunify360-agent rstatus`, start a first scan of `/home`, and keep Proactive Defense in `LOG` mode and cleanup set to quarantine for the first weeks.

## Prerequisites

The installer is picky about the state it finds. Before running it:

- Update the panel and CustomBuild: `da update` followed by `./build update` in `/usr/local/directadmin/custombuild`.

- Enable ModSecurity if you want the Imunify360 WAF. Imunify installs its own ruleset and takes over management of ModSecurity, but it needs the engine present: `./build set modsecurity yes` and `./build modsecurity`. The `modsecurity_ruleset` option becomes irrelevant afterwards because Imunify replaces it.

- Decide what happens to CSF. Imunify360 has its own firewall and works alongside CSF, but two daemons managing the same iptables chains is the classic cause of “rules disappear after a restart”. The installer detects CSF and integrates with it; if you would rather have one firewall, uninstall CSF first with `./build set csf no` and `csf -x`, then remove it. CloudLinux has published a migration tool from ConfigServer to Imunify360 since ConfigServer’s closure; on DirectAdmin the simpler path is the clean uninstall.

- Have the license key from the Imunify portal, or use IP-based licensing if the server IP is registered there.

## Installing Imunify360

```
cd /root
wget https://repo.imunify360.cloudlinux.com/defence360/i360deploy.sh
bash i360deploy.sh --key YOUR_LICENSE_KEY
```

Omit `--key` for an IP-based license. The script installs the agent packages from the Imunify repository, the DirectAdmin plugin, and, when ModSecurity is present, the WAF rules. It takes ten to twenty minutes. Reboot is not required. The plugin appears as **Imunify360** under Admin Level in the Evolution skin, and users get their own page showing malware findings for their files.

## Installing ImunifyAV

For the free scanner only:

```
cd /root
wget https://repo.imunify360.cloudlinux.com/defence360/imav-deploy.sh
bash imav-deploy.sh
```

No key is needed. ImunifyAV scans on a schedule and reports; cleanup requires an ImunifyAV+ license, which can be added later from the same interface without reinstalling. ImunifyAV does not include the firewall or WAF, so keep CSF and CustomBuild’s ModSecurity ruleset in place.

## First configuration

Most administration happens in the plugin, but the CLI is faster for a few things. Check the agent, run an initial scan and review the default policy:

```
imunify360-agent version
imunify360-agent rstatus
imunify360-agent malware on-demand start --path /home
imunify360-agent config show | head -n 60
```

Three settings deserve a decision on day one. **Proactive Defense** (PHP-level exploit blocking) should be in `LOG` mode for a week before switching to `KILL`, because it flags some legitimate obfuscated plugins. **WebShield**, the reverse proxy that presents captcha challenges, changes what the web server sees as the client IP; on DirectAdmin it inserts itself in front of Apache or LiteSpeed and you must ensure your logs and any rate limiting read the forwarded header.

The **Under Attack Mode** added in August 2026 and the layer-7 rate limiter are worth enabling on servers that see regular application-layer floods. And the **WAF for WordPress** rules, on by default since the end of August 2026, add WordPress-specific protection that overlaps with the general ruleset; leave them on unless a specific site breaks.

Malware cleanup defaults to quarantine rather than delete. Keep it that way for the first month so a false positive can be restored from the plugin.

## Common pitfall: the plugin loads but the WAF is inactive

The most frequent post-install complaint is that the interface shows the WAF as disabled or “ModSecurity not detected”. This happens when ModSecurity was not built before the installer ran, or when the web server was switched after installation. Build ModSecurity, then let Imunify reconfigure:

```
cd /usr/local/directadmin/custombuild && ./build modsecurity && ./build rewrite_confs
imunify360-agent features install ModSecurity
imunify360-agent rstatus
```

A related issue on OpenLiteSpeed and LiteSpeed Enterprise: Imunify supports both, but the WAF rules are loaded through the LiteSpeed-style configuration, so `./build rewrite_confs` after any LiteSpeed change is what makes them active again.

## Verify

Confirm the agent is registered and the components are up:

```
imunify360-agent rstatus
imunify360-agent list
imunify360-agent malware history list --limit 5
systemctl status imunify360 --no-pager
```

For Imunify360, test the WAF with a request that should be blocked, such as a query string containing an obvious SQL injection payload, and check that the plugin’s incidents page records it. Drop a harmless EICAR test file into a user’s `public_html` and confirm the next scan reports and quarantines it. Finally, make sure CSF (if kept) and Imunify are not fighting: `csf -ra` followed by `imunify360-agent rstatus` should leave both reporting healthy, and `iptables -L -n | head` should show Imunify’s chains still present after the CSF restart. If you removed CSF, re-check the [server security audit](/scripts/server-security-audit/) output, since Imunify’s firewall does not cover the port-exposure checks that CSF handled.

## Install Imunify360 DirectAdmin at a glance

**Official documentation:** [Imunify360 documentation](https://docs.imunify360.com/), [DirectAdmin documentation](https://docs.directadmin.com/), [Linux man pages](https://man7.org/linux/man-pages/).

**Related guides:** [Exim, Dovecot or DirectAdmin still serving the old certificate after renewal](https://srvscripts.com/guides/directadmin-old-certificate-exim-dovecot/) · [KernelCare on cPanel and DirectAdmin servers: setup, verification and rollback](https://srvscripts.com/guides/kernelcare-setup-cpanel-directadmin/) · [Enabling ModSecurity with OWASP CRS or Comodo rules on DirectAdmin and managing per-domain exclusions](https://srvscripts.com/guides/directadmin-modsecurity-owasp-crs/).

## Frequently asked questions

### Can Imunify360 run alongside CSF on DirectAdmin?

Yes, the installer detects CSF and integrates with it, but two daemons managing the same iptables chains is the usual cause of rules vanishing after a restart. If you want a single firewall, remove CSF cleanly with `./build set csf no` and `csf -x` before installing, and keep the security audit script for the port checks CSF used to do.

### What is the difference between ImunifyAV and Imunify360?

ImunifyAV is the free malware scanner that detects and reports; ImunifyAV+ adds cleanup for a fee. Imunify360 is the full suite with the reputation firewall, ModSecurity WAF, Proactive Defense for PHP, WebShield and malware cleanup. ImunifyAV can be upgraded from the same interface without reinstalling.

### Why does Imunify360 say ModSecurity is not detected on DirectAdmin?

The WAF needs the ModSecurity engine built by CustomBuild before the installer runs, and a web-server switch afterwards can break the integration. Run `./build modsecurity && ./build rewrite_confs`, then `imunify360-agent features install ModSecurity`, and check `imunify360-agent rstatus`.
