On Apache/LiteSpeed web servers, the attacker's IP is written to .htaccess within seconds and cut off with a 403 Forbidden — without letting it consume server CPU.
MODULES / Auto-Block
Cut off within seconds once the threshold is crossed
Auto-Block
Block threatening IPs instantly at the firewall and web server level. Details on NextPcap's active IPS module and setup.
- FIREWALL
- CLOUDFLARE
- AUTOMATIC
[ PURPOSE & VALUE ]
What does Auto-Block do?
What sets NextPcap apart from competitors is that it is not a passive observer. The moment an attacker launches a SQL Injection attack against your website or a brute-force attempt against your server's SSH port, NextPcap's Auto-Block module is triggered instantly upon detection. It blocks the attacker's IP address at the server level, preventing further requests from reaching your system.
[ FEATURES ]
What Auto-Block delivers
Performs database-level allowlist checks to prevent accidental blocking of your own sysadmins, pentest teams, or business partners' IP addresses.
Consolidates blocked IPs, the reason each was blocked, which site triggered it, and the rule ID responsible — all in one panel.
[ HOW IT WORKS ]
Live in three steps
Incoming signals are scored by risk.
IPs that cross the threshold are flagged automatically.
An instant block is applied via firewall/Cloudflare.
[ RELATED MODULES ]
Works together with Auto-Block
[ FAQ ]
Frequently asked questions about Auto-Block
Within seconds of detection — the block is applied instantly via .htaccess or the firewall/Cloudflare API.
No — the allowlist ensures any IP you've marked as trusted is never blocked.
See Auto-Block live
Headquarters: Ankara · iletisim@nextpacketcapture.com