Brute force detection with exponential-decay pressure scoring, 57 service rules, 8 firewall backends, GeoIP enrichment, and multi-channel alerting
-
Updated
Apr 24, 2026 - Shell
Brute force detection with exponential-decay pressure scoring, 57 service rules, 8 firewall backends, GeoIP enrichment, and multi-channel alerting
LockWall - free Windows Server brute-force protection for RDP, OWA & SQL Server. Closed-source freeware.
🛡️AI-assisted fail2ban alternative for Linux. Detects attacking IPs in your logs and bans them with escalating strikes — locally via nftables and at the Cloudflare edge. Dry-run by default. Self-hosted, AGPL-3.0.
Lightweight Linux firewall and automatic IP-ban engine — a modern Fail2Ban/CSF alternative with nftables and iptables support.
Lightweight zero-dependency SSH brute-force detector via concurrent-connection counting; multi-channel alerts, Qinglong-ready
Cloudflare-aware abuse swatter for cPanel + CSF: scores web-log IPs on behavioral signals + threat-intel and blocks attackers on the right plane — CSF for direct-to-origin, Cloudflare WAF for proxied — so it never firewalls a CF edge.
Lightweight SSH & login attack alerter daemon — real-time alerts via Slack/Telegram/Discord/webhook
Multi-server SSH attack intel: central SOC dashboard + lightweight log-shipper agents over Tailscale. React UI, stdlib Python API, SSO login, public abusers feed.
Server and application security engine: log-driven attack detection, IP banning, reputation and anomaly scoring, live panel. Source-available, no redistribution.
Server bouncer — ban web scanners & SSH brute-forcers via nftables. One curl install.
A lightweight SSH intrusion autoblocker & security CLI. Pylos monitors systemd journals for auth failures, dynamically managing iptables/ip6tables to ban malicious IPv4/IPv6 addresses. Features include SQLite persistence, automatic ban expiration, CIDR whitelisting, and CI/CD Debian packaging.
Zoraxy plugin: detects scanners in Zoraxy's access log and blocks them at Cloudflare's edge (IP List + WAF rule), optionally in Zoraxy's own blacklist. Blocks expire. Dry-run by default.
Single-binary edge guardian for Linux: detect & ban scanners/brute-force at nftables + per-site health monitoring. Zero deps, one-line install, built-in dashboard.
JScript event handlers for hMailServer 5.7.1: country blocking, AbuseIPDB check, auto-ban on failed logins, recipient probes and connection floods, daily aligned log. Secrets stay in a separate file. Needs Disconnect.exe.
To associate your repository with the fail2ban-alternative topic, visit your repo's landing page and select "manage topics."