Real-time SSH intrusion detection that monitors failed login attempts, automatically blocks offending IPs via
iptables, and fires instant Telegram alerts — all from a single Python script.
SSH Journal Logs ──► monitor.py ──► Failed attempt detected?
│
┌───────────────┴───────────────┐
│ │
IP in Whitelist? Not whitelisted
│ │
Skip — safe IP Count attempts
│
≥ 3 failed attempts?
│
┌─────────┴──────────┐
│ │
Block via iptables Telegram Alert 🚨
| Feature | Details |
|---|---|
| 📡 Real-time monitoring | Tails journalctl SSH logs live via subprocess |
| 🔢 Configurable threshold | Block after N failed attempts (default: 3) |
| 🚫 Auto IP blocking | Drops traffic using iptables -A INPUT -s <IP> -j DROP |
| 📋 Whitelist support | Protect trusted IPs from ever being blocked |
| 📲 Telegram alerts | Instant bot notification when an IP gets blocked |
| 🔁 Stateful tracking | Per-IP attempt counter persists across log lines |
ssh-monitor/
├── monitor.py # Main monitoring script
├── white_list # One trusted IP per line
└── README.md
git clone https://github.com/YOUR_USERNAME/ssh-monitor.git
cd ssh-monitorpip install requestsEdit monitor.py and fill in your credentials:
TOKEN = 'YOUR_BOT_TOKEN' # From @BotFather on Telegram
CHAT_ID = 'YOUR_CHAT_ID' # Your personal or group chat IDGet your bot token: Message @BotFather on Telegram →
/newbot
Get your chat ID: Message @userinfobot
echo "192.168.1.1" >> white_list
echo "10.0.0.5" >> white_listsudo python3 monitor.py
sudois required foriptablescommands.
____Security Monitoring Has Just Started____
Failed attempt 1 from : 203.0.113.42
Failed attempt 2 from : 203.0.113.42
Failed attempt 3 from : 203.0.113.42
BLOCKED: 203.0.113.42
And on your phone simultaneously:
🚨 تنبيه أمني: تم حظر IP 203.0.113.42 بعد 3 محاولات فاشلة.
| Variable | Location | Default | Description |
|---|---|---|---|
MAX_ATTEMPTS |
monitor.py |
3 |
Failed attempts before blocking |
WHITE_LIST_FILE |
monitor.py |
white_list |
Path to your whitelist file |
TOKEN |
monitor.py |
— | Telegram bot token |
CHAT_ID |
monitor.py |
— | Telegram chat/user ID |
When an IP exceeds MAX_ATTEMPTS:
sudo iptables -A INPUT -s <IP> -j DROPThis silently drops all incoming packets from that IP at the kernel level — no response sent, connection simply times out for the attacker.
To view blocked IPs:
sudo iptables -L INPUT -n --line-numbersTo unblock an IP manually:
sudo iptables -D INPUT -s <IP> -j DROP- Persist blocked IPs across reboots (
iptables-persistent) - GeoIP lookup on blocked IPs
- Email alert support alongside Telegram
- SQLite logging for historical analysis
- Integrate with Splunk for SIEM correlation
This tool is built for educational purposes and home lab environments. Test it in a controlled setup before deploying on production systems. Always ensure you whitelist your own IP before running.
Laith Hatem — Cybersecurity Analyst | Network Engineer
GitHub · LinkedIn