Security, monitoring and incident response
Security findings should lead to an action, not another dashboard.
Bring firewall events, malware findings, vulnerabilities, Cloudflare and incident actions into one security view.
Findings tied to a resourceOpen-source security stackCloudflare edge integration
QuroPanel
Security, monitoring and incident response
Search tools, domains…
12Websites
4.8 GBDisk
28Mailboxes
9Databases
Websites
Domains
Email
Files
Databases
WordPress
Applications
Security
Backups
Metrics
Runtime
Billing
Illustration of the QuroShield interface, drawn from the interface specification. Real screenshots replace this once the software is built.
Who it is for
Security analysts, administrators and anyone on call
Host and edge
- nftables policy generated from structured rules, not raw input
- CrowdSec behaviour detection with firewall remediation
- Coraza WAF running the OWASP Core Rule Set
- Cloudflare WAF, rate limits and origin protection
Detection
- ClamAV and YARA for malware and web shells
- File-integrity monitoring that separates expected deploys from unexplained changes
- Vulnerability scanning across OS packages and dependencies
- Secret scanning before a deployment is allowed through
Response
- Quarantine, block, suspend or revoke straight from a finding
- Automated playbooks with a human approval step
- Incident timeline with the evidence attached
- Post-incident report and corrective actions
Audit
- Immutable audit log: actor, original actor, resource, result
- Impersonation always recorded against the real administrator
- Retention policy and external SIEM delivery
- No passwords or session tokens are ever written to a log
Boundaries
What it deliberately will not do
Every one of these is a design decision, not a missing feature.
- No claim of being unbreakable. The goal is to prevent, detect quickly, contain automatically, keep evidence and recover.
- Certification is not asserted. QuroShield produces a technical readiness report; formal compliance needs a qualified audit.
- AI never disables a firewall, reveals a secret or terminates an account.
Other workspaces
Follow the build
The roadmap shows what is specified, what is being built and what is still only planned.
View the roadmapContribute
Drivers, integrations, translations and documentation are all places to start.
How to contributeReport a security issue
Responsible disclosure, with a stated response commitment.
Disclosure policy