SysWarden

Open-source, host-local Linux security orchestrator combining nftables enforcement, system telemetry, threat-intelligence feeds, out-of-band WAAP log analysis and a terminal dashboard. It requires Linux administration and is not an inline proxy.

Open Source

SysWarden Source Code

Author

duggytuxy

Description

Active Defense and HIDS/HIPS/WAAP Out-of-Band Orchestration for Critical Linux Infrastructure

#abuseipdb-integration#blocklists#cybersecurity-tools#docker-security#firewall#firewall-configuration#firewall-rules#firewalld#ipset-lists#iptables#ipv4-address#linux#malicious-ips#nftables#security-tools#syswarden#ufw#waf#wazuh#wireguard

Homepage

https://syswarden.io

Repository

  • LicenseGPL-3.0
  • Created09 Feb 26
  • Primary languageGo
  • Size52,245 KB
  • Stars328
  • Forks28
  • Watchers328

Language Usage

Language Usage

Project Health

  • Last commit1 day ago
  • Open issuesNone
  • Latest releasev4.03.3

Recent Commits

  • 🔐Laurent M🔐(28 Aug 26)

    Fix : bind release qualification to the eight-cell matrix (#133) Co-authored-by: duggytuxy <[email protected]>

  • 🔐Laurent M🔐(28 Aug 26)

    Fix : declare package license metadata (#132) Co-authored-by: duggytuxy <[email protected]>

  • 🔐Laurent M🔐(28 Aug 26)

    Fix : make attacker metrics evidence-based (#131) Co-authored-by: duggytuxy <[email protected]>

  • 🔐Laurent M🔐(28 Aug 26)

    Docs : disclose TUI OSINT enrichment source (#130) Co-authored-by: duggytuxy <[email protected]>

  • 🔐Laurent M🔐(28 Aug 26)

    Fix : provision embedded GeoIP policy data (#129) * Fix : provision embedded GeoIP policy data * Fix : satisfy core gosec test gate --------- Co-authored-by: duggytuxy <[email protected]>

  • 🔐Laurent M🔐(28 Aug 26)

    Minor : add typed operator policy foundation (#126) Co-authored-by: duggytuxy <[email protected]>

  • 🔐Laurent M🔐(27 Aug 26)

    Qualification : freeze v4.04.0 AMD64 matrix (#125) Co-authored-by: duggytuxy <[email protected]>

  • 🔐Laurent M🔐(27 Aug 26)

    CI : generalize release chain validation (#124) Co-authored-by: duggytuxy <[email protected]>

  • 🔐Laurent M🔐(27 Aug 26)

    Qualification: bind v4.03.3 Ubuntu rollback recovery (#123) Co-authored-by: duggytuxy <[email protected]>

  • 🔐Laurent M🔐(27 Aug 26)

    Fix : stabilize v4.03.3 package qualification (#122) Co-authored-by: duggytuxy <[email protected]>

  • 🔐Laurent M🔐(26 Aug 26)

    CI : avoid Go 1.26 fuzz deadline race (#121) Co-authored-by: duggytuxy <[email protected]>

  • 🔐Laurent M🔐(26 Aug 26)

    Qualification : repair v4.03.3 lifecycle qualification (#120) Co-authored-by: duggytuxy <[email protected]>

  • 🔐Laurent M🔐(26 Aug 26)

    CI : bind one-time v4.03.3 changelog seal (#119) Co-authored-by: duggytuxy <[email protected]>

  • 🔐Laurent M🔐(26 Aug 26)

    Patch : correct webhook, firewall and OSINT handling (#118) * Patch : correct webhook, firewall and OSINT handling * Patch : harden v4.03.3 package lifecycle qualification * Patch : qualify adversarial gosec fixtures * Patch : close native v4.03.3 qualification gaps * Patch : qualify v4.03.3 security fixtures * Patch : close v4.03.3 lint cleanup * Patch : close v4.03.3 native package gaps --------- Co-authored-by: duggytuxy <[email protected]>

  • 🔐Laurent M🔐(25 Aug 26)

    CI : make release inventory comparison portable (#117) Co-authored-by: duggytuxy <[email protected]>

  • dependabot[bot](25 Aug 26)

    Bump github/codeql-action/upload-sarif from 4.37.7 to 4.37.8 (#107) Bumps [github/codeql-action/upload-sarif](https://github.com/github/codeql-action) from 4.37.7 to 4.37.8. - [Release notes](https://github.com/github/codeql-action/releases) - [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md) - [Commits](https://github.com/github/codeql-action/compare/ff2f1c621b7f889edc0d3c761ac2e6a3f8cdb0dd...db488ddef3bf6cb639b32c2e9a7c0a7ea8271d28) --- updated-dependencies: - dependency-name: github/codeql-action/upload-sarif dependency-version: 4.37.8 dependency-type: direct:production update-type: version-update:semver-patch ... Signed-off-by: dependabot[bot] <[email protected]> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

  • 🔐Laurent M🔐(25 Aug 26)

    Qualification : bind v4.03.2 unsigned evidence SHA (#116) Co-authored-by: duggytuxy <[email protected]>

  • 🔐Laurent M🔐(25 Aug 26)

    Qualification : bind v4.03.2 release tip (#115) Co-authored-by: duggytuxy <[email protected]>

  • 🔐Laurent M🔐(25 Aug 26)

    Release : support AMD64 packages only (#114) Co-authored-by: duggytuxy <[email protected]>

  • 🔐Laurent M🔐(25 Aug 26)

    Qualification : pin ARM64 delegated UID probe (#113) Co-authored-by: duggytuxy <[email protected]>

  • 🔐Laurent M🔐(25 Aug 26)

    Qualification : preserve ARM64 crun owner across delegation (#112) Co-authored-by: duggytuxy <[email protected]>

  • 🔐Laurent M🔐(25 Aug 26)

    Qualification : stabilize ARM64 crun version attestation (#111) * Qualification : stabilize ARM64 crun version attestation * Documentation : enlarge official SysWarden hero logo --------- Co-authored-by: duggytuxy <[email protected]>

  • 🔐Laurent M🔐(25 Aug 26)

    Security : preserve read-only config preflight and centralize v4.03.2 docs (#110) Co-authored-by: duggytuxy <[email protected]>

  • 🔐Laurent M🔐(25 Aug 26)

    Qualification : seal systemd-capable ARM64 crun runtime (#109) Co-authored-by: duggytuxy <[email protected]>

  • dependabot[bot](25 Aug 26)

    Bump github.com/pelletier/go-toml/v2 in /src/core/syswarden-cli (#105) Bumps [github.com/pelletier/go-toml/v2](https://github.com/pelletier/go-toml) from 2.2.4 to 2.4.3. - [Release notes](https://github.com/pelletier/go-toml/releases) - [Commits](https://github.com/pelletier/go-toml/compare/v2.2.4...v2.4.3) --- updated-dependencies: - dependency-name: github.com/pelletier/go-toml/v2 dependency-version: 2.4.3 dependency-type: direct:production update-type: version-update:semver-minor ... Signed-off-by: dependabot[bot] <[email protected]> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> Co-authored-by: 🔐Laurent M🔐 <[email protected]>

  • dependabot[bot](25 Aug 26)

    Bump github.com/pelletier/go-toml/v2 in /src/core/syswarden-core (#106) Bumps [github.com/pelletier/go-toml/v2](https://github.com/pelletier/go-toml) from 2.2.4 to 2.4.3. - [Release notes](https://github.com/pelletier/go-toml/releases) - [Commits](https://github.com/pelletier/go-toml/compare/v2.2.4...v2.4.3) --- updated-dependencies: - dependency-name: github.com/pelletier/go-toml/v2 dependency-version: 2.4.3 dependency-type: direct:production update-type: version-update:semver-minor ... Signed-off-by: dependabot[bot] <[email protected]> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> Co-authored-by: 🔐Laurent M🔐 <[email protected]>

  • 🔐Laurent M🔐(25 Aug 26)

    Qualification : restore v4.03.2 ARM64 lifecycle under crun (#108) * Qualification : restore v4.03.2 ARM64 crun runtime * Qualification : bind PR108 release provenance * Qualification : complete PR108 ARM64 lifecycle fix --------- Co-authored-by: duggytuxy <[email protected]>

  • 🔐Laurent M🔐(24 Aug 26)

    Security : enforce v4.03.2 compliance release verdict (#104) Co-authored-by: duggytuxy <[email protected]>

  • 🔐Laurent M🔐(24 Aug 26)

    Qualification : repair v4.03.2 ARM64 init runtime (#103) Co-authored-by: duggytuxy <[email protected]>

  • 🔐Laurent M🔐(24 Aug 26)

    Qualification : stabilize v4.03.2 ARM64 lifecycle evidence (#102) * Qualification : stabilize v4.03.2 ARM64 lifecycle evidence * Qualification : bind PR102 release contract * Test : keep Alpine lifecycle mocks POSIX portable --------- Co-authored-by: duggytuxy <[email protected]>

SysWarden Reviews

More Linux Defenses

  • Clears cache and deletes temporary files very effectively. This frees up disk space, improves performance, but most importantly helps to protect privacy.

  • Locally checks for signs of a rootkit.

  • ClamTk is basically a graphical front-end for ClamAV, making it an easy to use, light-weight, on-demand virus scanner for Linux systems.

  • Firejail is a SUID sandbox program that reduces the risk of security breaches by restricting the running environment of untrusted applications using Linux namespaces and seccomp-bpf. Written in C, virtually no dependencies, runs on any modern Linux system, with no daemon running in the background, no complicated configuration, and it's super lightweight and super secure, since all actions are implemented by the kernel. It includes security profiles for over 800 common Linux applications. FireJail is recommended for running any app that may potential pose some kind of risk, such as torrenting through Transmission, browsing the web, opening downloaded attachments.

  • Open source GUI firewall for Linux, allowing you to block internet access for certain applications. Supports both simple and advanced mode, GUI and CLI options, very easy to use, lightweight/ low-overhead, under active maintenance and backed by a strong community. Installable through most package managers, or compile from source.

  • Open source intrusion prevention system capable of real-time traffic analysis and packet logging.

About the Data: SysWarden

Change History

Edit SysWarden Data

You can edit SysWarden's entry in this section of awesome-privacy.yml by submitting a PR to our GitHub repo.
Note that some of the information shown above has been aggregated from external sources, a list of these can be found data documentation.

Origin Data

Modify Data

API

You can access SysWarden's data programmatically via our API. Simply make a GET request to:

https://api.awesome-privacy.xyz/v1/services/syswarden

The REST API is free, no-auth and CORS-enabled. To learn more, view the API Docs or read the API Usage Guide.

Share SysWarden

Help your friends compare Linux Defenses, and pick privacy-respecting software and services.
Share SysWarden and Awesome Privacy with your network!