Self-hosted Linux server protector that ACTS, not just alerts. SIGSTOP runaway processes, iptables-ban brute-forcers, take incident snapshots. Single Rust binary.
-
Updated
May 7, 2026 - Rust
Self-hosted Linux server protector that ACTS, not just alerts. SIGSTOP runaway processes, iptables-ban brute-forcers, take incident snapshots. Single Rust binary.
Lightweight Rust intrusion-signal monitor for Linux VPS hosts with alerts, active response, baselines, and a fleet panel.
tamper resistant audit log
provides a Suricata Eve output for Kafka with Suricate Eve plugin
A simple trap for web crawlers
Intrusion detection and file integrity monitoring in rust.
A terminal-based Intrusion Prevention System (IPS) built in Rust. Visualize attacks and enforce firewall blocks in real-time.
UZYNTRA API Firewall is a high-performance API security engine that inspects, detects, and mitigates threats in real time through a programmable reverse proxy architecture.
Pico collects HC-SR04 sensor data and sends via MQTT
OS-level runtime security for AI agents. Tamper-proof monitoring, behavioral detection, and audit trails.
Lightning-fast Linux security scanner finds real threats in seconds, not hours. Cryptominers, CVEs, rootkits, memory threats, network attacks. Single binary, 100% local.
Desktop Linux file integrity monitor. Kernel-level filesystem watching, BLAKE3 hashing, HMAC-chained audit trail. Silent by default, local by design, deeply paranoid.
Defense-only AI attack detection daemon for small businesses. Watches logs, detects AI-orchestrated cyberattacks, blocks malicious IPs. Hebbian learning. MITRE ATT&CK mapped. Apache 2.0.
Rust Deterministic Streaming Guardian prevents LLM leaks
Host Intrusion Detection & Active Signaling System (HIDASS) for Linux kernel 5.15+. Implements a Stackelberg defender-leader game-theoretic model to expose interactive APTs via eBPF-driven TTY timing analysis (Welford/Shannon entropy) and adaptive zero-copy RingBuffer jitter injection. Built in Rust (no_std probe, Tokio user-space daemon).
Minimal manifest and installations of Talos LightSPD distributions for Snort 3.
A dual-module eBPF security research framework demonstrating offensive rootkit techniques (Shadow) and defensive runtime auditing (Aegis) for Linux kernel exploration.
A modular network detection & analysis platform with a packet engine, flow tracking, detection rules, threat intel (Sigma/YARA/IOC), and a REST dashboard. Rust core with Python plugin extensibility. MIT licensed.
Car-alarm-style intrusion guard for Linux desktops: a USB or Bluetooth remote arms a guard that locks your session, and touching the machine trips a countdown, a siren and a timestamped webcam still.
Live Windows intrusion watcher: tails pfirewall.log + Security 4624/4625, scores attackers with a decayed-reputation engine, auto-blocks hostile IPs via netsh advfirewall. No agent, no SaaS — a single statically-linked Rust binary.
To associate your repository with the intrusion-detection topic, visit your repo's landing page and select "manage topics."