Breach Harbor
Reads existing sshd, nginx and fail2ban logs to identify attacking IPs and blocks them in the local firewall
The product is a small agent for Linux servers that reads existing sshd, nginx and fail2ban log files to identify IP addresses attempting brute-force logins or scans and blocks them in the local firewall. It is for IT, operations and developer teams in businesses that manage their own Linux servers. It is delivered as an open-source agent installed with a single command that runs locally using nftables or iptables, operates in observe-only mode for 24 hours before blocking, and keeps all data on the machine by default.
Key features
- Reads existing sshd nginx fail2ban logs
- Scores IPs by local behavior
- Observe-only mode for 24 hours
- Blocks via nftables or iptables
- Exempts current SSH session address
- One command to flush rules
- Optional shared community blocklist
- Signed and checksummed releases
- No social media activity within the last 30 days
GTM channels
- Community
ICP
- DevOps sre teams
- IT teams
- Software developers