See what your host sees.
Bring host logs and supported upstream service signals into a native terminal workflow.
OPEN SOURCE. OPERATOR CONTROL.
Bring host signals, threat intelligence and nftables enforcement together. Keep security decisions close to the systems you protect.
Built for AMD64 Linux GPL-3.0-or-later

A CLEARER SECURITY PICTURE
A security layer built around explicit policy, local visibility and decisions an operator can inspect.
Bring host logs and supported upstream service signals into a native terminal workflow.
Combine validated threat feeds with operator-defined IP, ASN and country controls.
Apply validated decisions through nftables, with clear firewall ownership and local telemetry.
DESIGNED TO BE UNDERSTOOD
SysWarden analyzes host and application logs outside the request path. Validated policy decisions reach the Linux firewall.
Explore the architectureHost logs, supported service signals and threat intelligence.
Validate inputs and apply signatures and operator policy.
Publish validated decisions to nftables and record local telemetry.
BUNKERWEB INTEGRATION PLUGIN
Connect compatible BunkerWeb deployments to SysWarden. The integration plugin submits temporary bans through an authenticated HTTPS API, bringing application detections to the host firewall.
Read the integration guideCompatibility is version-specific. Follow the integration guide for supported plugin and SysWarden combinations.
TRUST YOU CAN EXAMINE
Follow the implementation, review security checks and verify the assets supplied with each release.
Read the security policySTART WITH THE RIGHT VERSION
Follow the version-specific documentation and check the supported distribution matrix before installing.
BEFORE YOU START
SysWarden analyzes supported application logs out of band. It does not proxy or sanitize HTTP traffic. Enforcement is applied through the host firewall.
Use the stable release and its documentation for a release-based installation. v4.10.0 is published and validated under IVV (Integration, Verification and Validation). Later source builds do not inherit that release verdict. Full IVVQ, adding Qualification, applies to Upgrade generations such as v5.00.0.
The planned v5.00.0 work packages, dependencies and acceptance criteria are tracked in the public roadmap on GitHub.
BUILT IN THE OPEN
Report an issue, improve the documentation or help fund the next round of engineering and qualification.