A real-time console to monitor, control and protect every subdomain in your fleet: DDoS defense, WAF, rate limiting, browser challenges, and per-domain access gates — all in one place.
DEMO · SAMPLE DATA ONLYSYN flood protection, half-open connection limits, bogon filtering, port-scan detection and UDP amplification protection at the kernel edge.
Validates HTTP methods, user agents, headers, referer, origin, cookies, paths, query strings, content types and protocol — malformed requests never reach your origin.
Signature detection for SQL injection, XSS, path traversal, command injection, LFI, RFI, Shellshock and scanner activity — plus custom rules.
Token-bucket per-IP throttling, sliding-window burst control, per-path limits and adaptive cooldown that red/yellow/green auto-tunes under load.
Baseline learning, anomaly scoring and automatic mitigation level selection. On attack, mitigation escalates from normal → aggressive → emergency.
CAPTCHA v2 + hold gate that verifies human visitors before content is served. Whitelisted IPs and verified browsers pass without friction.
Multi-node synchronization of blocklists, whitelists and config across all edge servers so a block on one node applies everywhere.
Real-time notifications for attacks, blocks and mode changes delivered straight to your messaging endpoint.
Normal / Aggressive / Emergency mode buttons and a quick-block IP box right in the header — action in under a second.
Sites page).The production dashboard is protected by HTTP Basic Auth. The docs, status and feature subdomains are public and demonstrate the same GarudaShield edge protection live.