What is website malware monitoring?
Website malware monitoring is the regular, automated re-scanning of a site and its server so infections are found soon after they arrive, not weeks later when Google or a customer notices. PatientZero monitors from the server side, which means it sees webshells, cron jobs and hidden files that an external check cannot.
Most compromises are quiet at first. A backdoor is uploaded, a scheduled task is added, and nothing visible changes until the site starts redirecting visitors or sending spam. By then the attacker may have had access for some time. Scheduled scans shorten that window. Monitoring runs 24/7 on every plan.
How does the "Needs attention" queue work?
The "Needs attention" queue on the Overview collects everything that needs a decision: servers that failed or have not been tested, jobs in progress, servers ready for hardening and scans with findings. Each item has one clear next step, a Harden or Fix button, so nothing sits unnoticed in a report.
# Overview · Needs attention (fictional)
acme-prod-01 Connected · apply shipped hardening playbooks [Harden]
shop-eu-02 dfir-fast · 12 findings [Fix]
shop-eu-02 malware-intelligence · 47 findings [Fix]
acme-staging malware-intelligence · 0 findings Clean
For agencies and teams managing many servers, this replaces checking each dashboard in turn. See PatientZero for agencies.
Is server-side monitoring better than an external scanner?
They answer different questions, so PatientZero uses both. External checks see what a visitor sees: downtime, blacklist warnings, visible redirects. Server-side scans see what a visitor cannot: webshells in uploads, crontab loops, new SSH keys and rogue admins. Most serious compromises only show up from the inside, often long before anything is visible.
| Signal | External check | Server-side scan |
|---|---|---|
| Site down or defaced | Yes | Partly |
| Visible redirects and spam | Sometimes | Yes |
| Webshells and backdoors | No | Yes |
| Cron and systemd persistence | No | Yes |
| New SSH keys and rogue admins | No | Yes |
Want to see what an outside check picks up today? Start with our two-minute security triage.
What happens when monitoring finds malware?
When monitoring finds malware, you are alerted, the finding appears in the queue and our team starts triage as soon as we are aware. Because every plan includes unlimited malware removal, a re-infection is cleaned at no extra cost, and the entry point is found and closed so it does not happen again.
- Alert. New findings are flagged with severity and the affected site.
- Contain. Malicious files are quarantined with evidence kept; rogue users and keys are removed.
- Root cause. The Forensic scan timeline shows how the attacker got in.
- Harden. Playbooks close that route, then a follow-up scan confirms the server is clean.
If you are not yet a customer and something is wrong now, go straight to emergency help, or start with our security triage.