Proof

A real cleanup, on a really hacked server.

No staged demo. In July 2026 a production WordPress site was actively infected. We pointed Ally at it and recorded what happened. Nothing below is invented — and nothing was deleted.

Production CyberPanel server · 90 live sites Actively infected WordPress site July 14, 2026
1 · Investigate — read-only

One sentence in. No changes yet.

The owner typed one line: "scan the site for malware and clean up anything you find." Ally's pre-mission scout — read-only — immediately surfaced the suspect files (8f3a2c.php, b71d40.php, two malware folders) and proposed an investigation plan. Only after approval did it stream a live malware scan into the workspace.

2 · Quarantine — never delete

13 items moved. Zero deleted. Site back: HTTP 200.

The webshell had replicated across the whole account. Ally quarantined all 13 items — 11 webshell copies and 2 malware folders — with mv, never rm, so every move could be undone. It read the webshell's actual content to classify it (a file-upload backdoor with a fake "Nyanpasu!!!" upload form), confirmed the site's folder was clean, then loaded the site itself: HTTP 200. The recording below is that exact moment, unedited.

3 · The deeper hunt

It kept digging — and then it stopped to ask.

A full incident-response mission (eleven read-only recon steps) traced the deeper compromise: three more malicious files — including a 9 MB backdoor disguised as a WordPress file — and 5 fake admin accounts an attacker had planted, one posing as root. Then the important part: Ally paused for approval before deleting anything. Evidence preserved, destructive decisions handed to the human.

Unedited screen capture — the live quarantine, then the site loading clean. GIF · 2.4 MB · loads only when you press play

The honest footnote

One finding in the deeper hunt was a false positive: Ally flagged repeated logins from an IP that turned out to be our own scanner. What matters is what happened next — with uncertainty present, Ally handed the destructive cleanup back to the human instead of acting. That's the safety model doing its job, and we're keeping the note here because trust is the product.

Where it stands today

The 13 quarantined items sit in a locked folder on the server — reversible, evidence intact — and the site verified clean with HTTP 200. The deeper findings (3 files, 5 fake admins) are surfaced and documented, awaiting the owner's decision. Ally doesn't delete on its own. Ever.

Proven, not promised

Numbers we can stand behind.

Pre-launch means no customer counts and no uptime graphs. These are the numbers we actually have — all from documented tests.

13

webshell items quarantined on a live production site — moved, never deleted

5

fake admin accounts uncovered — including one posing as root

404

automated safety tests guard every command before it can run

<$2

of AI spend for the entire break-it red-team campaign

Point it at your server next.

Two servers free. It will look before it touches — and ask before anything risky.

Try for Free Watch how it works