OPEN SOURCE. OPERATOR CONTROL.

Linux defense.
Your host.
Your rules.

Bring host signals, threat intelligence and nftables enforcement together. Keep security decisions close to the systems you protect.

Built for AMD64 Linux GPL-3.0-or-later

01 / THE DEFENSE PATH
Conceptual architecture: observed signals feed policy decisions, which drive nftables enforcement and evidence.
Host-local decisions. Kernel-level enforcement.Conceptual architecture illustration
STABLE RELEASEv4.10.0 RELEASE ASSURANCEv4.10.0 IVV validated WHAT COMES NEXTv5.00.0 Public roadmap

A CLEARER SECURITY PICTURE

Understand the signal.
Control the response.

A security layer built around explicit policy, local visibility and decisions an operator can inspect.

See what your host sees.

Bring host logs and supported upstream service signals into a native terminal workflow.

HIDS / LOG ANALYSIS / TUI

Make your policy explicit.

Combine validated threat feeds with operator-defined IP, ASN and country controls.

IP / CIDR / ASN / GEO

Enforce on the host.

Apply validated decisions through nftables, with clear firewall ownership and local telemetry.

HIPS / NFTABLES / EVIDENCE

DESIGNED TO BE UNDERSTOOD

Three stages.
Clear boundaries.

SysWarden analyzes host and application logs outside the request path. Validated policy decisions reach the Linux firewall.

Explore the architecture
  1. 01

    Observe

    Host logs, supported service signals and threat intelligence.

  2. 02

    Decide

    Validate inputs and apply signatures and operator policy.

  3. 03

    Enforce

    Publish validated decisions to nftables and record local telemetry.

BUNKERWEB INTEGRATION PLUGIN

Web protection.
Host enforcement.
A connected defense.

Connect compatible BunkerWeb deployments to SysWarden. The integration plugin submits temporary bans through an authenticated HTTPS API, bringing application detections to the host firewall.

Read the integration guide
BunkerWebApplication protection + plugin
L7
Authenticated HTTPS API
SysWardenPolicy + ownership + expiration
HOST
Validated temporary bans
nftablesLinux firewall enforcement
KERNEL

Compatibility is version-specific. Follow the integration guide for supported plugin and SysWarden combinations.

TRUST YOU CAN EXAMINE

Read the code.
Inspect the evidence.

Follow the implementation, review security checks and verify the assets supplied with each release.

Read the security policy

START WITH THE RIGHT VERSION

Your Linux.
Your deployment.

Follow the version-specific documentation and check the supported distribution matrix before installing.

02 / CURRENT SOURCE

Build from the source.

Build an exact source revision with the documented checks. Local builds retain their own identity.

Build and install from source

BEFORE YOU START

A few useful answers.

Is SysWarden an inline web application firewall?

SysWarden analyzes supported application logs out of band. It does not proxy or sanitize HTTP traffic. Enforcement is applied through the host firewall.

Which version should I install?

Use the stable release and its documentation for a release-based installation. v4.10.0 is published and validated under IVV (Integration, Verification and Validation). Later source builds do not inherit that release verdict. Full IVVQ, adding Qualification, applies to Upgrade generations such as v5.00.0.

Where can I follow the v5 roadmap?

The planned v5.00.0 work packages, dependencies and acceptance criteria are tracked in the public roadmap on GitHub.

BUILT IN THE OPEN

Stronger with the community.

Report an issue, improve the documentation or help fund the next round of engineering and qualification.