Skip to content

About

Real-time SSH brute-force detector that auto-blocks attacking IPs via iptables and sends instant Telegram alerts. Built with Python on Linux.

Resources

Stars

0 stars

Watchers

0 watching

Forks

Latest commit

 

History

3 Commits

Folders and files

NameName
Last commit message
Last commit date
 
 
 
 
 
 

Repository files navigation

🛡️ SSH Brute-Force Monitor & Auto-Blocker

Real-time SSH intrusion detection that monitors failed login attempts, automatically blocks offending IPs via iptables, and fires instant Telegram alerts — all from a single Python script.


📸 How It Works

SSH Journal Logs  ──►  monitor.py  ──►  Failed attempt detected?
                                              │
                              ┌───────────────┴───────────────┐
                              │                               │
                         IP in Whitelist?              Not whitelisted
                              │                               │
                        Skip — safe IP             Count attempts
                                                        │
                                               ≥ 3 failed attempts?
                                                        │
                                              ┌─────────┴──────────┐
                                              │                    │
                                       Block via iptables   Telegram Alert 🚨

✨ Features

Feature Details
📡 Real-time monitoring Tails journalctl SSH logs live via subprocess
🔢 Configurable threshold Block after N failed attempts (default: 3)
🚫 Auto IP blocking Drops traffic using iptables -A INPUT -s <IP> -j DROP
📋 Whitelist support Protect trusted IPs from ever being blocked
📲 Telegram alerts Instant bot notification when an IP gets blocked
🔁 Stateful tracking Per-IP attempt counter persists across log lines

📁 Project Structure

ssh-monitor/
├── monitor.py        # Main monitoring script
├── white_list        # One trusted IP per line
└── README.md

⚙️ Setup & Usage

1. Clone the repo

git clone https://github.com/YOUR_USERNAME/ssh-monitor.git
cd ssh-monitor

2. Install dependencies

pip install requests

3. Configure your Telegram bot

Edit monitor.py and fill in your credentials:

TOKEN   = 'YOUR_BOT_TOKEN'    # From @BotFather on Telegram
CHAT_ID = 'YOUR_CHAT_ID'      # Your personal or group chat ID

Get your bot token: Message @BotFather on Telegram → /newbot
Get your chat ID: Message @userinfobot

4. Add trusted IPs to the whitelist

echo "192.168.1.1" >> white_list
echo "10.0.0.5"    >> white_list

5. Run the monitor

sudo python3 monitor.py

sudo is required for iptables commands.


🧪 Sample Output

____Security Monitoring Has Just Started____
Failed attempt 1 from : 203.0.113.42
Failed attempt 2 from : 203.0.113.42
Failed attempt 3 from : 203.0.113.42
BLOCKED: 203.0.113.42

And on your phone simultaneously:

🚨 تنبيه أمني: تم حظر IP 203.0.113.42 بعد 3 محاولات فاشلة.

🔧 Configuration

Variable Location Default Description
MAX_ATTEMPTS monitor.py 3 Failed attempts before blocking
WHITE_LIST_FILE monitor.py white_list Path to your whitelist file
TOKEN monitor.py — Telegram bot token
CHAT_ID monitor.py — Telegram chat/user ID

🔒 How Blocking Works

When an IP exceeds MAX_ATTEMPTS:

sudo iptables -A INPUT -s <IP> -j DROP

This silently drops all incoming packets from that IP at the kernel level — no response sent, connection simply times out for the attacker.

To view blocked IPs:

sudo iptables -L INPUT -n --line-numbers

To unblock an IP manually:

sudo iptables -D INPUT -s <IP> -j DROP

🗺️ Roadmap

  • Persist blocked IPs across reboots (iptables-persistent)
  • GeoIP lookup on blocked IPs
  • Email alert support alongside Telegram
  • SQLite logging for historical analysis
  • Integrate with Splunk for SIEM correlation

⚠️ Disclaimer

This tool is built for educational purposes and home lab environments. Test it in a controlled setup before deploying on production systems. Always ensure you whitelist your own IP before running.


👤 Author

Laith Hatem — Cybersecurity Analyst | Network Engineer
GitHub · LinkedIn

About

Real-time SSH brute-force detector that auto-blocks attacking IPs via iptables and sends instant Telegram alerts. Built with Python on Linux.

Resources

Stars

0 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages