Critical checks run every 10 minutes. Typical wall-clock cost on a busy shared host is a few seconds; the runner enforces the 10-minute cadence even when a tick takes longer.
The tables below name the finding identifiers CSM emits, grouped by area. Most are standalone scheduled checks; a few (for example the http_* traffic findings and bad_asn_outbound) are produced by a parent scheduled check – the access-log brute-force scan and the periodic connection scan respectively – rather than being independently scheduled.
Outbound connection whose destination resolves (via GeoLite2-ASN) to a bad or unexpected autonomous system. Config detection.bad_asn_outbound: blocked_asns (always bad) and/or allowed_asns (allowlist mode – anything outside is bad). Classified for every process including root (the periodic connection scan); non-root connections are also flagged in real time by the live BPF tracker. Off by default; the third leg of the host_takeover incident chain
WordPress login brute force (wp-login.php, xmlrpc.php)
http_scanner_profile
Source IPs whose traffic is mostly probe-error responses across many distinct paths in one scheduled scan window
http_claimed_bot_unverified
High-volume claimed crawler traffic while reverse-DNS verification is still pending; challenge-routed when the challenge subsystem is enabled
http_ua_spoof
IP hitting the per-IP spoof threshold with a search-engine bot UA that fails reverse-DNS verification, or with scripting/headless/empty UAs when those opt-in flags are enabled
http_distributed_flood
Many already-abusive HTTP source IPs hitting the same vhost in one scheduled scan window
http_asn_crawl
A single ASN distributing expensive, uncacheable requests across many addresses while one account’s PHP worker pool is saturated. Reverse-proxy ASNs and operator allowlists are excluded; Critical findings can carry the specific source CIDRs eligible for temporary blocking.
Mail queue buildup (spam outbreak indicator). Exim aborts when it cannot write its own log, and the daemon’s sandbox makes /var/log read-only, so the queue query runs as a transient unit forked by PID 1. Hosts without systemd-run query exim directly.
mail_queue_unavailable
The queue depth could not be read, so buildup detection is inactive. Reported instead of assuming the queue is empty.
mail_per_account
Per-account email volume spikes
All Exim queue reads and actions started by the daemon run as transient services outside its read-only filesystem sandbox. This includes queue composition, safe backscatter flushing, and PHP relay freeze or thaw actions. If systemd-run is unavailable, CSM runs them directly; a host without Exim skips the Exim-only queue check. The target command is attempted at most once, and cancellation during the wrapper probe stops it before execution.
The MySQL audit exempts mysql@localhost only when MariaDB confirms its stock
socket authentication setup with password authentication disabled. Modified
authentication, other host literals, and accounts whose setup cannot be verified
remain reportable.
IPs against external threat databases and optional rspamd history. Passive HTTP/cPanel sightings are High; SSH and mail-auth activity is Critical
local_threat_score
Aggregated score from internal attack database
modsec_audit
ModSecurity audit log parsing
The local threat score retains evidence attributed to the server itself. Such
records can represent forwarded attacks or a compromised local process; firewall
protection against blocking the server does not establish that traffic is safe.
Runs on every supported platform unless noted below. The daemon auto-detects OS and panel at startup and silently skips cPanel-specific checks on plain Linux hosts (no “not found” spam).
cPanel-only (skipped on plain Ubuntu/AlmaLinux):
api_tokens, whm_access, cpanel_logins, cpanel_filemanager – read WHM API and cPanel session logs
wp_bruteforce – iterates /home/*/public_html/*/wp-login.php and per-domain access logs. The domlog pass ranks recent logs first and honors thresholds.domlog_max_files, thresholds.domlog_tail_lines, and thresholds.domlog_max_age_min.
Plain Linux equivalents that still provide coverage:
mail_queue runs on any host where Exim is installed and is skipped when there is no Exim queue.
Access log brute-force detection (wp_login_bruteforce, xmlrpc_abuse) runs against the detected web server’s access log (/var/log/nginx/access.log or /var/log/httpd/access_log), so WordPress brute-force alerts still fire on non-cPanel hosts – they just rely on the live log watcher rather than per-domain domlog scanning.
modsec_audit runs on any host with ModSecurity installed.
ssh_logins, SSH brute force, PAM listener, firewall, kernel modules, RPM/DEB integrity, and threat intelligence all run on every supported platform.