2026-04-13 09:12:57 [INFO] ./install-syswarden.sh
2026-04-13 09:12:57 [INFO] Detecting Operating System and
Firewall Backend...
2026-04-13 09:12:57 [INFO] OS: Debian GNU/Linux
2026-04-13 09:12:57 [INFO] Detected Firewall Backend: nftables
2026-04-13 09:12:57 [INFO] Auto-whitelisting current admin SSH
session IP: IP_ADMIN
2026-04-13 09:12:57 [INFO] Checking dependencies...
2026-04-13 09:12:57 [INFO] Updating apt repositories...
2026-04-13 09:13:06 [WARN] Installing package: rsyslog
2026-04-13 09:13:10 [WARN] Installing package: WireGuard &
Qrencode
2026-04-13 09:13:13 [WARN] Installing package: ipset
2026-04-13 09:13:16 [WARN] Installing package: fail2ban
2026-04-13 09:13:22 [INFO] All dependencies check complete.
2026-04-13 09:13:22 [INFO] Detecting Operating System and
Firewall Backend...
2026-04-13 09:13:22 [INFO] OS: Debian GNU/Linux
2026-04-13 09:13:22 [INFO] Detected Firewall Backend: nftables
2026-04-13 09:13:36 [INFO] Pre-Flight Checklist acknowledged.
Starting interactive configuration...
2026-04-13 09:13:39 [INFO] Ensuring SSH TCP Forwarding is
strictly DISABLED...
2026-04-13 09:13:39 [INFO] SSH Port configured as: 42022
2026-04-13 09:13:42 [INFO] WireGuard DISABLED.
2026-04-13 09:13:44 [INFO] Docker integration DISABLED.
2026-04-13 09:13:46 [INFO] OS Hardening ENABLED. Sudo/Cron will
be strictly restricted.
2026-04-13 09:13:55 [INFO] Geo-Blocking ENABLED for: ru cn kp ir
2026-04-13 09:14:13 [INFO] ASN Blocking ENABLED. Custom: [AS30823
AS210644 AS200593 AS202425], Spamhaus: [n]
2026-04-13 09:14:17 [INFO] HA Cluster Sync DISABLED.
2026-04-13 09:14:44 [INFO] Configuring Rsyslog to forward ONLY
Fail2ban logs to SIEM...
2026-04-13 09:14:44 [INFO] SIEM Log Forwarding is ACTIVE.
(Target: TEST01:514/tcp)
2026-04-13 09:14:44 [INFO] Generating Fail2ban configuration
(Universal Mode)...
2026-04-13 09:14:44 [INFO] Purged default jail.d configurations
to enforce Zero Trust.
2026-04-13 09:14:44 [INFO] Systemd-journald detected. OS-native
jails will be optimized for maximum performance.
2026-04-13 09:14:44 [INFO] Fail2ban infrastructure whitelist
enforced: 127.0.0.1/8 ::1 fe80::/10
2026-04-13 09:14:45 [INFO] Nginx logs detected. Enabling Nginx
Jail.
2026-04-13 09:14:45 [INFO] Web logs available. Configuring
WordPress Jail.
2026-04-13 09:14:45 [INFO] Web logs detected. Enabling Drupal
Guard.
2026-04-13 09:14:45 [INFO] WireGuard detected. Enabling UDP Jail.
2026-04-13 09:14:45 [INFO] PAM/Auth logs detected. Enabling
Privilege Escalation Guard (Su/Sudo).
2026-04-13 09:14:45 [INFO] Kernel logs detected. Enabling Port
Scanner Guard.
2026-04-13 09:14:45 [INFO] Web access logs detected. Enabling
Reverse Shell & RCE Guard.
2026-04-13 09:14:45 [INFO] Web access logs detected. Enabling
AI-Bot Guard.
2026-04-13 09:14:45 [INFO] Web access logs detected. Enabling
Bad-Bot & Scanner Guard.
2026-04-13 09:14:45 [INFO] Web access logs detected. Enabling
Layer 7 Anti-DDoS Guard.
2026-04-13 09:14:45 [INFO] Web access logs detected. Enabling
WebShell Upload Guard.
2026-04-13 09:14:45 [INFO] Web access logs detected. Enabling
SQLi & XSS Payload Guard.
2026-04-13 09:14:45 [INFO] Web access logs detected. Enabling
Stealth Secrets Hunter Guard.
2026-04-13 09:14:45 [INFO] Web access logs detected. Enabling
SSRF & Cloud Metadata Guard.
2026-04-13 09:14:45 [INFO] Web access logs detected. Enabling
JNDI & SSTI Guard.
2026-04-13 09:14:45 [INFO] Web access logs detected. Enabling API
Mapper Guard.
2026-04-13 09:14:45 [INFO] Web access logs detected. Enabling
Behavioral IDOR Guard.
2026-04-13 09:14:45 [INFO] Web access logs detected. Enabling
Advanced LFI Guard.
2026-04-13 09:14:45 [INFO] Web access logs detected. Enabling
Behavioral Scanner Guard.
2026-04-13 09:14:45 [INFO] Web access logs detected. Enabling
Open Proxy & Exotic Method Guard.
2026-04-13 09:14:45 [INFO] Web access logs detected. Enabling
Generic Brute-Force & Password Spraying Guard.
2026-04-13 09:14:45 [INFO] Web access logs detected. Enabling
PrestaShop Guard.
2026-04-13 09:14:45 [INFO] Web access logs detected. Enabling
Atlassian Guard.
2026-04-13 09:14:45 [INFO] Starting Fail2ban service...
2026-04-13 09:14:50 [INFO] User selected: Critical Blocklist
2026-04-13 09:14:50 [INFO] Benchmarking mirrors...
2026-04-13 09:14:52 [INFO] Fetching list from
https://raw.githubusercontent.com/duggytuxy/...
2026-04-13 09:14:52 [INFO] Download success.
2026-04-13 09:14:52 [INFO] Fetching CINS Army & Blocklist.de
threat feeds...
2026-04-13 09:14:53 [INFO] Sanitizing OSINT IPs and merging with
the main blocklist...
2026-04-13 09:14:53 [INFO] OSINT feeds successfully merged into
the core firewall memory.
2026-04-13 09:14:53 [INFO] Scanning User-Space for actively
listening TCP services...
2026-04-13 09:14:53 [INFO] Whitelisted active services (TCP):
[42022,80]
2026-04-13 09:14:53 [INFO] Configuring Nftables via Atomic
Transaction (Zero-Downtime)...
2026-04-13 09:14:54 [INFO] Populating Nftables sets atomically in
chunks (Bypassing memory limits)...
2026-04-13 09:14:54 [INFO] Applying Atomic Nftables Transaction
to the Kernel...
2026-04-13 09:14:54 [INFO] Saving SysWarden Nftables table to
isolated config...
2026-04-13 09:14:54 [INFO] Injecting include directive into
/etc/nftables.conf...
2026-04-13 09:14:55 [INFO] Configuring universal IPSet
persistence for boot survival...
2026-04-13 09:14:56 [INFO] Geo-Blocking list updated
successfully.
2026-04-13 09:14:56 [INFO] Spamhaus ASN-DROP integration skipped
by user.
2026-04-13 09:15:01 [INFO] ASN Blocklist updated successfully.
2026-04-13 09:15:01 [INFO] Applying massive downloaded lists to
active firewall...
2026-04-13 09:15:01 [INFO] Scanning User-Space for actively
listening TCP services...
2026-04-13 09:15:01 [INFO] Whitelisted active services (TCP):
[42022,80]
2026-04-13 09:15:02 [INFO] Configuring Nftables via Atomic
Transaction (Zero-Downtime)...
2026-04-13 09:15:02 [INFO] Populating Nftables sets atomically in
chunks (Bypassing memory limits)...
2026-04-13 09:15:02 [INFO] Applying Atomic Nftables Transaction
to the Kernel...
2026-04-13 09:15:02 [INFO] Saving SysWarden Nftables table to
isolated config...
2026-04-13 09:15:03 [INFO] Configuring universal IPSet
persistence for boot survival...
2026-04-13 09:15:03 [INFO] Fail2ban is ACTIVE. Jails:
drupal-auth, nginx-http-auth, nginx-scanner...
2026-04-13 09:15:03 [INFO] Installation of the advanced telemetry
engine (Backend)...
2026-04-13 09:15:05 [INFO] Generating the Enterprise SaaS Nginx
Dashboard (SPA/Sidebar/CSP)...
2026-04-13 09:15:05 [INFO] Downloading local JetBrains Mono
fonts...
2026-04-13 09:15:05 [INFO] Generating Self-Signed RSA 4096 TLS
Certificate...
2026-04-13 09:15:06 [INFO] Configuring Nginx reverse proxy for
port 9999...
2026-04-13 09:15:06 [INFO] Opening Port 9999 in OS Firewall to
enable Nginx routing...
2026-04-13 09:15:07 [INFO] Dashboard UI secured by Nginx at
https://IP_SERVER:9999
2026-04-13 09:15:10 [INFO] Skipping AbuseIPDB reporting setup.
2026-04-13 09:15:12 [INFO] Skipping Wazuh Agent installation.
2026-04-13 09:15:12 [INFO] Automatic updates enabled.
2026-04-13 09:15:12 [INFO] Applying strict OS hardening (Crontab,
Sudo/Wheel, Profiles)...
2026-04-13 09:12:57 [INFO] ./install-syswarden.sh
2026-04-13 09:12:57 [INFO] Detecting Operating System and
Firewall Backend...
2026-04-13 09:12:57 [INFO] OS: Debian GNU/Linux
2026-04-13 09:12:57 [INFO] Detected Firewall Backend: nftables
2026-04-13 09:12:57 [INFO] Auto-whitelisting current admin SSH
session IP: IP_ADMIN
2026-04-13 09:12:57 [INFO] Checking dependencies...
2026-04-13 09:12:57 [INFO] Updating apt repositories...
2026-04-13 09:13:06 [WARN] Installing package: rsyslog
2026-04-13 09:13:10 [WARN] Installing package: WireGuard &
Qrencode
2026-04-13 09:13:13 [WARN] Installing package: ipset
2026-04-13 09:13:16 [WARN] Installing package: fail2ban
2026-04-13 09:13:22 [INFO] All dependencies check complete.
2026-04-13 09:13:22 [INFO] Detecting Operating System and
Firewall Backend...
2026-04-13 09:13:22 [INFO] OS: Debian GNU/Linux
2026-04-13 09:13:22 [INFO] Detected Firewall Backend: nftables
2026-04-13 09:13:36 [INFO] Pre-Flight Checklist acknowledged.
Starting interactive configuration...
2026-04-13 09:13:39 [INFO] Ensuring SSH TCP Forwarding is
strictly DISABLED...
2026-04-13 09:13:39 [INFO] SSH Port configured as: 42022
2026-04-13 09:13:42 [INFO] WireGuard DISABLED.
2026-04-13 09:13:44 [INFO] Docker integration DISABLED.
2026-04-13 09:13:46 [INFO] OS Hardening ENABLED. Sudo/Cron will
be strictly restricted.
2026-04-13 09:13:55 [INFO] Geo-Blocking ENABLED for: ru cn kp ir
2026-04-13 09:14:13 [INFO] ASN Blocking ENABLED. Custom: [AS30823
AS210644 AS200593 AS202425], Spamhaus: [n]
2026-04-13 09:14:17 [INFO] HA Cluster Sync DISABLED.
2026-04-13 09:14:44 [INFO] Configuring Rsyslog to forward ONLY
Fail2ban logs to SIEM...
2026-04-13 09:14:44 [INFO] SIEM Log Forwarding is ACTIVE.
(Target: TEST01:514/tcp)
2026-04-13 09:14:44 [INFO] Generating Fail2ban configuration
(Universal Mode)...
2026-04-13 09:14:44 [INFO] Purged default jail.d configurations
to enforce Zero Trust.
2026-04-13 09:14:44 [INFO] Systemd-journald detected. OS-native
jails will be optimized for maximum performance.
2026-04-13 09:14:44 [INFO] Fail2ban infrastructure whitelist
enforced: 127.0.0.1/8 ::1 fe80::/10
2026-04-13 09:14:45 [INFO] Nginx logs detected. Enabling Nginx
Jail.
2026-04-13 09:14:45 [INFO] Web logs available. Configuring
WordPress Jail.
2026-04-13 09:14:45 [INFO] Web logs detected. Enabling Drupal
Guard.
2026-04-13 09:14:45 [INFO] WireGuard detected. Enabling UDP Jail.
2026-04-13 09:14:45 [INFO] PAM/Auth logs detected. Enabling
Privilege Escalation Guard (Su/Sudo).
2026-04-13 09:14:45 [INFO] Kernel logs detected. Enabling Port
Scanner Guard.
2026-04-13 09:14:45 [INFO] Web access logs detected. Enabling
Reverse Shell & RCE Guard.
2026-04-13 09:14:45 [INFO] Web access logs detected. Enabling
AI-Bot Guard.
2026-04-13 09:14:45 [INFO] Web access logs detected. Enabling
Bad-Bot & Scanner Guard.
2026-04-13 09:14:45 [INFO] Web access logs detected. Enabling
Layer 7 Anti-DDoS Guard.
2026-04-13 09:14:45 [INFO] Web access logs detected. Enabling
WebShell Upload Guard.
2026-04-13 09:14:45 [INFO] Web access logs detected. Enabling
SQLi & XSS Payload Guard.
2026-04-13 09:14:45 [INFO] Web access logs detected. Enabling
Stealth Secrets Hunter Guard.
2026-04-13 09:14:45 [INFO] Web access logs detected. Enabling
SSRF & Cloud Metadata Guard.
2026-04-13 09:14:45 [INFO] Web access logs detected. Enabling
JNDI & SSTI Guard.
2026-04-13 09:14:45 [INFO] Web access logs detected. Enabling API
Mapper Guard.
2026-04-13 09:14:45 [INFO] Web access logs detected. Enabling
Behavioral IDOR Guard.
2026-04-13 09:14:45 [INFO] Web access logs detected. Enabling
Advanced LFI Guard.
2026-04-13 09:14:45 [INFO] Web access logs detected. Enabling
Behavioral Scanner Guard.
2026-04-13 09:14:45 [INFO] Web access logs detected. Enabling
Open Proxy & Exotic Method Guard.
2026-04-13 09:14:45 [INFO] Web access logs detected. Enabling
Generic Brute-Force & Password Spraying Guard.
2026-04-13 09:14:45 [INFO] Web access logs detected. Enabling
PrestaShop Guard.
2026-04-13 09:14:45 [INFO] Web access logs detected. Enabling
Atlassian Guard.
2026-04-13 09:14:45 [INFO] Starting Fail2ban service...
2026-04-13 09:14:50 [INFO] User selected: Critical Blocklist
2026-04-13 09:14:50 [INFO] Benchmarking mirrors...
2026-04-13 09:14:52 [INFO] Fetching list from
https://raw.githubusercontent.com/duggytuxy/...
2026-04-13 09:14:52 [INFO] Download success.
2026-04-13 09:14:52 [INFO] Fetching CINS Army & Blocklist.de
threat feeds...
2026-04-13 09:14:53 [INFO] Sanitizing OSINT IPs and merging with
the main blocklist...
2026-04-13 09:14:53 [INFO] OSINT feeds successfully merged into
the core firewall memory.
2026-04-13 09:14:53 [INFO] Scanning User-Space for actively
listening TCP services...
2026-04-13 09:14:53 [INFO] Whitelisted active services (TCP):
[42022,80]
2026-04-13 09:14:53 [INFO] Configuring Nftables via Atomic
Transaction (Zero-Downtime)...
2026-04-13 09:14:54 [INFO] Populating Nftables sets atomically in
chunks (Bypassing memory limits)...
2026-04-13 09:14:54 [INFO] Applying Atomic Nftables Transaction
to the Kernel...
2026-04-13 09:14:54 [INFO] Saving SysWarden Nftables table to
isolated config...
2026-04-13 09:14:54 [INFO] Injecting include directive into
/etc/nftables.conf...
2026-04-13 09:14:55 [INFO] Configuring universal IPSet
persistence for boot survival...
2026-04-13 09:14:56 [INFO] Geo-Blocking list updated
successfully.
2026-04-13 09:14:56 [INFO] Spamhaus ASN-DROP integration skipped
by user.
2026-04-13 09:15:01 [INFO] ASN Blocklist updated successfully.
2026-04-13 09:15:01 [INFO] Applying massive downloaded lists to
active firewall...
2026-04-13 09:15:01 [INFO] Scanning User-Space for actively
listening TCP services...
2026-04-13 09:15:01 [INFO] Whitelisted active services (TCP):
[42022,80]
2026-04-13 09:15:02 [INFO] Configuring Nftables via Atomic
Transaction (Zero-Downtime)...
2026-04-13 09:15:02 [INFO] Populating Nftables sets atomically in
chunks (Bypassing memory limits)...
2026-04-13 09:15:02 [INFO] Applying Atomic Nftables Transaction
to the Kernel...
2026-04-13 09:15:02 [INFO] Saving SysWarden Nftables table to
isolated config...
2026-04-13 09:15:03 [INFO] Configuring universal IPSet
persistence for boot survival...
2026-04-13 09:15:03 [INFO] Fail2ban is ACTIVE. Jails:
drupal-auth, nginx-http-auth, nginx-scanner...
2026-04-13 09:15:03 [INFO] Installation of the advanced telemetry
engine (Backend)...
2026-04-13 09:15:05 [INFO] Generating the Enterprise SaaS Nginx
Dashboard (SPA/Sidebar/CSP)...
2026-04-13 09:15:05 [INFO] Downloading local JetBrains Mono
fonts...
2026-04-13 09:15:05 [INFO] Generating Self-Signed RSA 4096 TLS
Certificate...
2026-04-13 09:15:06 [INFO] Configuring Nginx reverse proxy for
port 9999...
2026-04-13 09:15:06 [INFO] Opening Port 9999 in OS Firewall to
enable Nginx routing...
2026-04-13 09:15:07 [INFO] Dashboard UI secured by Nginx at
https://IP_SERVER:9999
2026-04-13 09:15:10 [INFO] Skipping AbuseIPDB reporting setup.
2026-04-13 09:15:12 [INFO] Skipping Wazuh Agent installation.
2026-04-13 09:15:12 [INFO] Automatic updates enabled.
2026-04-13 09:15:12 [INFO] Applying strict OS hardening (Crontab,
Sudo/Wheel, Profiles)...