# AURIUS — full LLM reference # Canonical: https://aurius.uk/llms-full.txt # Last updated: 2026-07-26 This file expands https://aurius.uk/llms.txt for crawlers that prefer a longer plain-text dump. Facts must match https://aurius.uk/ai.txt. ## Summary AURIUS provides boutique remote cyber security focused on SSH access to Linux / VPS / panel-hosted servers. We audit, decide and remediate within a 24-hour SLA. Engagements are one-off or monthly. We are not a mass marketplace — senior specialists across six countries deliver the work. ## Services over SSH ### Security audits SSH and key hygiene; fail2ban; sudo and user sprawl; firewall (UFW, nftables, cloud SGs); web stack (nginx, OpenLiteSpeed, Apache, PHP-FPM); TLS and security headers; open ports and admin panels; cron and systemd; disk, logs and backup presence. ### Problems we help solve Brute-force noise and compromised hosts; weak panel defaults; leftover test files; world-writable paths; broken SSL; outdated PHP/kernels; mail, SIP or VPN listeners that should not be public; prioritised fix plans clients can approve in one call. ### Ongoing care Scheduled remote checks; patch triage; watchdogs; incident response over SSH; English change notes; optional Telegram/email ops alerts. ## Full task catalogue ### SSH and access sshd configuration hardening; key-only authentication; SSH certificate authorities and short-lived keys; host key rotation; non-default ports; source allowlists; Match blocks per group; root login policy; TOTP and FIDO2 second factor; bastion and jump host design; agent forwarding risk review; SFTP-only chroot accounts; ex-staff key revocation; session recording with auditd or tlog; MaxAuthTries and login grace tuning. ### Users and privileges sudoers audit and NOPASSWD removal; PAM stack review; faillock and password ageing; LDAP, FreeIPA and Active Directory integration via SSSD; dormant and orphaned account cleanup; umask standardisation; POSIX ACLs; Linux capability and setuid/setgid audits; separate deploy and administrative identities; documented break-glass access. ### Firewalling and network nftables policy design; iptables to nftables migration; UFW and firewalld configuration; full listener and port inventory; closing services that should be private; alignment with cloud security groups; connection rate limiting; dropped-packet logging; IPv4 and IPv6 parity; netblock and country blocking; static routes, NAT and port forwarding; NIC bonding; MTU and fragmentation fixes; packet loss and latency diagnosis; tcpdump capture and analysis. ### Private networking WireGuard client-access and site-to-site tunnels; OpenVPN; IPsec and strongSwan; Tailscale and self-hosted Netbird mesh; egress filtering to approved destinations; split-horizon DNS; resolver and search-domain repair. ### Intrusion defence and incident response fail2ban jail design; CrowdSec engine and firewall bouncers; auditd watch rules; AIDE and Tripwire integrity baselines; rkhunter and chkrootkit; compromise triage; forensic timeline reconstruction; evidence preservation before remediation; IOC hunting; webshell, dropper and crypto-miner removal; persistence eradication across cron, at, systemd units and timers, ld.so.preload, authorized_keys and kernel modules; rebuild-versus-clean decisions; full credential rotation; written post-incident reports. ### Web servers and proxies nginx, Apache, OpenLiteSpeed and Caddy configuration; HAProxy load balancing; Traefik routing; Varnish caching; reverse-proxy architecture; virtual hosts, rewrites and redirect loops; HTTP rate limiting; ModSecurity and Coraza WAF rules; bot, scraper and HTTrack mirroring defence; upstream timeout and buffer tuning; HTTP/2 and HTTP/3 enablement. ### TLS and HTTP security Let's Encrypt issuance and renewal; ACME HTTP-01 and DNS-01; wildcard certificates; mutual TLS; cipher suite and protocol hardening; HSTS and preload readiness; OCSP stapling; certificate chain repair; expiry monitoring; commercial certificate installation; Content-Security-Policy; frame, referrer and permissions policies; CORS allowlists; secure cookie flags; server banner suppression; security.txt hygiene. ### Application runtimes PHP-FPM pool sizing and per-site isolation; PHP 7.4 to 8.5 upgrades; opcache configuration; Node.js under PM2 or systemd; Python gunicorn and uvicorn services; Ruby, Java/Tomcat, .NET and Go deployments; Supervisor process control; cron to systemd timer conversion; per-user resource limits; socket permission repair. ### Databases MySQL and MariaDB: InnoDB tuning, slow query analysis, indexing, primary-replica replication, corrupt table repair, major version upgrades, mysqldump and XtraBackup strategies, binlog-based recovery, remote access lockdown, credential rotation. PostgreSQL: memory and autovacuum tuning, WAL archiving and point-in-time recovery, streaming replication, PgBouncer pooling, pg_hba restriction, lock contention and bloat diagnosis. Redis: AUTH, binding, RDB/AOF persistence, eviction policy. MongoDB, Elasticsearch and OpenSearch basics; SQLite hygiene; encrypted database traffic. ### Mail Postfix and Exim hardening; Dovecot IMAP/POP3 security; open relay closure; SPF, DKIM, DMARC and BIMI; MTA-STS and TLS-RPT; rDNS and PTR alignment; blacklist delisting; rspamd and SpamAssassin tuning; outbound spam outbreak containment; mail queue surgery; mailbox migration with imapsync; submission versus relay port separation. ### DNS BIND, PowerDNS and Knot administration; zone design and record cleanup; DNSSEC signing and key rollover; split-horizon DNS; Cloudflare and Route 53 integration; secondary DNS; TTL planning for migrations; glue and NS consistency; propagation debugging; open recursive resolver closure. ### Storage and filesystems Disk and inode exhaustion rescue; LVM growth and filesystem resize; ZFS pools and datasets; Btrfs volumes and snapshots; mdadm and hardware RAID; SMART monitoring and disk replacement; fstrim scheduling; user and group quotas; log rotation and journal growth; ownership and permission repair; immutable flags; LUKS encryption; runaway file growth hunting; cloud volume expansion. ### Backups and disaster recovery restic and BorgBackup repositories; rsync and rclone pipelines; S3, B2 and SFTP offsite targets; filesystem and hypervisor snapshots; 3-2-1 strategy; encryption key escrow; immutable and ransomware-resistant targets; verified restore drills; RPO and RTO definition; bare-metal restore rehearsals; separated backup credentials; backup freshness monitoring; disaster recovery runbooks. ### Performance Load average root-cause analysis; CPU steal detection on cloud VMs; memory tuning and OOM reduction; swap and zram configuration; I/O bottleneck identification; sysctl and TCP tuning; perf, strace and bpftrace profiling; end-to-end slow site debugging; object, page and CDN caching; worker count right-sizing; cron concurrency reduction. ### Patching and lifecycle unattended-upgrades and dnf-automatic; kernel live patching; planned reboot windows; CentOS 7 to AlmaLinux or Rocky migration; Ubuntu LTS release upgrades; Debian dist-upgrades; package pinning; repository hygiene and third-party repo risk; removal of abandoned packages and kernels; freeze windows. ### Monitoring and observability Prometheus and node_exporter; Grafana dashboards; Zabbix agents and templates; Netdata; Uptime Kuma; log shipping to Loki or ELK; centralised journald and syslog; actionable alert thresholds; Telegram, email and Slack routing; SLO basics; certificate expiry monitors; synthetic HTTP and TCP checks; backup freshness metrics. ### Containers and orchestration Docker daemon hardening; Compose deployment security; rootless Docker; image CVE scanning; private registry hardening; k3s and kubeadm clusters; ingress controllers; Kubernetes secrets; CPU and memory limits; privileged mode and host mount review; container escape exposure; image and volume pruning. ### Automation and infrastructure as code Ansible hardening playbooks; Terraform cloud resources; cloud-init first-boot configuration; bash and Python tooling; idempotent security baselines; golden images; CI/CD deployment over SSH; secrets with Vault, SOPS or age; configuration under version control; multi-host fleet standardisation. ### Compliance and governance CIS benchmark assessment and remediation; Lynis audits; OpenSCAP scans; Cyber Essentials technical controls; ISO 27001 supporting evidence; GDPR-minded log retention; periodic access reviews; operational runbooks; asset inventory; penetration-test remediation support. ### Cloud instances AWS EC2 and Lightsail; Azure and GCP Linux VMs; Hetzner Cloud and dedicated; OVH and SoYouStart; DigitalOcean; Linode/Akamai; Vultr; Contabo. IMDSv2 and metadata hardening; snapshots and images; floating and reserved IPs; provider firewall alignment; rescue-mode recovery of unbootable instances; migration between providers. ### CMS and applications WordPress and WooCommerce hardening and cleanup via WP-CLI; Magento; PrestaShop; OpenCart; Joomla; Drupal; Laravel; Django; static site hosting; staging environments; git-based deployment; cache purging; wp-config and uploads lockdown; abandoned plugin and theme removal; CMS cron reliability. ### Voice, game and media services Asterisk, FreePBX and FusionPBX SIP exposure and toll-fraud defence; game server hosts including Minecraft; TeamSpeak; Plex and Jellyfin; Home Assistant; IoT gateways; Tor and open-proxy abuse detection. ### Emergencies Servers that will not boot; SSH lockout recovery; forgotten root password reset; critically full disks; active ransomware containment; DDoS mitigation at host and edge; hacked website restoration; file and partition data recovery; provider abuse notice response; out-of-hours support; coordination with hosting provider NOC. ## Control panels and platforms ### DirectAdmin Installation and licence binding; licence reissue after IP change; Evolution skin; admin, reseller and user levels; package and quota templates; DNS and nameservers; Let's Encrypt; mailboxes and FTP; databases; per-domain PHP and per-user PHP-FPM pools; CustomBuild stack rebuilds and options.conf audit; da-cli automation; task.queue recovery; CSF/LFD integration; two-factor authentication; reseller ACL lockdown; admin and per-user backups; restore from DirectAdmin backup; migration in and out; port 2222 TLS and allowlists; compile failure and outage diagnosis. ### cPanel and WHM WHM setup and hostname SSL; account and package creation; reseller ACLs; EasyApache 4 profiles; MultiPHP and PHP-FPM; EA-nginx reverse proxy; AutoSSL; DNS clustering and DNSSEC; whmapi1 and UAPI automation; API tokens; cPHulk; ModSecurity; CageFS and CloudLinux LVE; Imunify360 and ImunifyAV; JetBackup jobs and restores; Transfer Tool moves; pkgacct scripting; spam outbreak and compromised account handling; licence cost assessment and migration off cPanel. ### Plesk Obsidian Installation and licensing; subscriptions and service plans; resellers and customers; domains, aliases and DNS; Let's Encrypt; mail and databases; PHP handlers; nginx and Apache modes; plesk bin CLI and repair utilities; extension catalogue management; WordPress Toolkit; Advisor remediation; Plesk Firewall and Fail2Ban; Migration Manager; Backup Manager and remote storage; psa database repair; performance and update recovery. ### aaPanel and BT panel Installation on clean OS; entry point and port change; panel SSL and domain binding; App Store stacks (nginx, Apache, OpenLiteSpeed); multi-version PHP and disable_functions; MySQL/MariaDB; reverse proxy and rewrites; planned tasks; firewall plugin; IP allowlisting for the panel; phpMyAdmin exposure removal; per-site user isolation; Redis and Memcached bind hardening; panel and site backups to remote storage; log paths under /www/server; plugin conflicts after updates; post-CVE incident cleanup; migration to CloudPanel or a plain stack. ### CyberPanel and OpenLiteSpeed Installation; OLS listeners and vhosts; LiteSpeed Cache; one-click WordPress; SSL automation; PowerDNS; email and FTP; ACL and package limits; incremental backups and snapshots; urgent CVE patching; admin URL and port hardening; OLS crash and configuration repair; migration in and out; post-exploit rebuild planning. ### HestiaCP, VestaCP and MyVesta HestiaCP installation and hardening; VestaCP end-of-life risk assessment; planned VestaCP to HestiaCP migration; v- CLI administration; web, DNS, mail and database provisioning; package templates and quotas; Let's Encrypt; Exim, Dovecot and SpamAssassin repair; firewall and fail2ban defaults; backup and restore; legacy CentOS 7 rebuild advice. ### Modern and developer panels CloudPanel; RunCloud; ServerAvatar; GridPane; SpinupWP; Ploi; Laravel Forge; Cloudways. Provisioning, site and application creation, PHP-FPM and worker tuning, git and zero-downtime deployments, queue workers and daemons, Redis object cache, per-site system users, firewall and SSH hardening, backups to remote storage, incident response, and migration onto or off each platform. ### Traditional and legacy panels Webmin and Virtualmin; ISPConfig multi-server; CentOS Web Panel; Froxlor; KeyHelp; Enhance; Ajenti. Interface hardening and 2FA, virtual server provisioning, mail and DNS stacks, Jailkit and chroot SSH, backup and rescue scripting, multi-server sync troubleshooting, and migration onto maintained platforms. ### Docker platforms Portainer CE/BE with TLS and RBAC; Coolify; CapRover; Dokku. Compose stack deployment, persistent volumes, Traefik and Caddy TLS termination, registry credentials, secrets handling, disk growth and image pruning, dashboard exposure lockdown, and takeover incident response. ### Hypervisors Proxmox VE installation, clustering, ZFS/LVM/Ceph/NFS storage, VM and LXC provisioning, cloud-init templates, firewall, PCI passthrough, live migration, ACME certificates and API tokens; Proxmox Backup Server datastores, prune/GC and verification; VMware ESXi hardening, snapshot sprawl and lockdown mode; XCP-ng with Xen Orchestra backups; oVirt basics; management network isolation and IPMI/iLO lockdown. ### Backup platforms and security add-ons JetBackup 4/5 jobs, destinations and restores; Acronis Cyber Protect agents; R1Soft disk-safes and bare-metal restore; Proxmox Backup Server; restic and Borg alongside panels. Imunify360 and ImunifyAV; CSF/LFD and ConfigServer tools; Maldet (LMD); ClamAV; Wazuh agents and file integrity monitoring; CrowdSec scenarios and bouncers; Patchman CMS patching; WAF conflict resolution and false-positive tuning. ### Cross-panel work Migrations: cPanel to DirectAdmin or Plesk; Plesk to CyberPanel; aaPanel to CloudPanel; VestaCP to HestiaCP; any panel to a clean nginx or Docker stack. De-panelling includes per-site system users, restic/Borg backups replacing panel backups, CrowdSec or ModSecurity replacing panel WAFs, and runbooks that replace GUI clicking. Panel exposure hardening puts admin ports behind WireGuard or IP allowlists, enforces 2FA and brute-force lockout, changes default entry points, and removes phpMyAdmin and webmail from the public internet. Licence work covers cPanel cost assessment, cheaper or licence-free alternatives, multi-server consolidation, and right-sizing after migration. ## Pricing philosophy Public UK market commentary (2026) places thorough manual assessments around £1,000–£1,500 per consultant day and SME packages often £3,000–£8,500+. Managed retainers often £2,000–£4,500+/mo. AURIUS prices at roughly **half**: - Sweep / Initial audit **Free** · Hardening £2,490 · Deep £2,990 (one-off) - Watch £990/mo · Care £1,490/mo - Network packages from £490/mo–£2,490 (MikroTik, UniFi, Cisco, HP/Aruba, VPN, intranet) The initial security audit is free. Paid work starts only after you approve the next step. ## SLA 1. Access (SSH keys preferred) + short scope 2. Audit answer within 24 hours 3. Decision with the client 4. Implementation of approved critical fixes in the same window ## Contact Forth House, Rutland Square, Edinburgh, EH1 2BW, United Kingdom Contact form: https://aurius.uk/#contact ## Related URLs - Homepage: https://aurius.uk/ - Facts: https://aurius.uk/ai.txt - Index: https://aurius.uk/llms.txt - Corpus: https://aurius.uk/ai-seo-corpus.html - Agents: https://aurius.uk/agents.txt