{"repo":"sammwyy/spear","free":true,"listed":false,"github":"https://github.com/sammwyy/spear","clone":"git clone https://github.com/sammwyy/spear.git","description":"modular and extensible Kasane Teto based NIDS/HIDS (intrusion detection system)","language":"Go","stars":16,"topics":["cybersecurity","ddos","dos","fail2ban","firewall","hids","http","ids","ips","linux"],"license":null,"category":"security-tools","readme_excerpt":"Spear Features - Core: - 🔩 Extensible config loader. - 🚐 Flexible event bus (external modules) - 📦 Cached shared file watcher. - 🧩 Runtime plugin loader. - API: - 📡 Integrated logger. Easy to log plugin events. - 🧩 Rich plugin API. - ⌛ Timewindow API. - 🌩 Trigger registry. - 📋 Module registry. - Modules: - 🔐 Authwatch: Watch for unsuccess/success login access and sudo request. - Supports: SSH, FTP, HTTP, Sudo. - Configurable hits and timewindow. - Support fallback log file for multiple OS compatibility (Debian, Arch, Fedora) - 🔦 VerticalScan: Watch for vertical port scanning - Detects SYN scan, FIN scan, Xmas tree, Null scan, Fragmented packets. - Configurable hits and timewindow. - 🔑 Userwatch: Watch for user changes. - Detect user creation/deletion. - Detect group changes. - Detect password changes. - 📁 Filewatch: Watch for file and directory changes. - Detect file and directories. - Common file events: create, delete, modified, rename. - Common directory eventss: add/remove children files. - Triggers: - 👁 Logs: Log all activity to .csv, .json or .log file. To-do - [ ] More modules (flooding, suspicious TTL, IP source routing, fragmented spoofing, DNS tunneling, more authwatch protocols: RDP, FTP, SMTP, MySQL..., heuristic, iptables/nftables integration, syslog) - [ ] More triggers (email/SMTP, Discord, Telegram, Slack) - [ ] A dashboard? (ELK stack, Grafana, Prometheus) - [X] Critical integrity check (/etc/passwd, /etc/shadow) log changes and more - [ ] AIDE h","default_branch":null,"files":null,"tree":[],"storefront":"/r/sammwyy","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/sammwyy/spear/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}