Battle-tested intrusion prevention tools for self-hosted Linux infrastructure. Download, deploy, and protect your server in minutes.
All packages are unmodified releases mirrored directly from official GitHub repositories. Checksums provided.
Scans log files for repeated authentication failures and automatically updates firewall rules to ban offending IPs. Supports SSH, Apache, Nginx, Postfix, and 400+ custom filters. Integrates seamlessly with iptables, nftables, and firewalld.
Next-generation collaborative security engine. Detects threats using crowd-sourced intelligence and blocks malicious IPs in real time. Supports nftables, iptables, cloud WAF bouncers, and 200+ detection scenarios.
Real-time port scan detector with automatic attacker blacklisting. Monitors unused TCP/UDP ports for unauthorized probes, instantly blackholes scanners via kernel routing. Includes 60+ pre-configured port profiles and ignore lists.
Pre-integrated bootable image with all three tools, hardened base OS, nftables templates, and Grafana monitoring.
Bootable security appliance ISO for x86_64 bare-metal or VM deployment. Bundles Fail2Ban, CrowdSec, and PortSentry with a pre-hardened Debian 12 base, automated nftables ruleset generator, Grafana telemetry dashboard, and a web-based management console. Ideal for rapid deployment on new infrastructure or lab environments.
One-liner commands for major Linux distributions.