Open source AMD64 Linux Source v4.04.0

Active defense for hardened Linux hosts

SysWarden is a host-local security orchestrator combining authoritative nftables policy, HIDS/HIPS telemetry, bounded threat intelligence, out-of-band WAAP log analysis, authenticated high availability and a native terminal dashboard.

Current sourcev4.04.0
Latest stable releasev4.03.3
LicenseGPL-3.0-or-later

Protection operators can review

SysWarden keeps enforcement close to the protected host and keeps its operating boundaries explicit.

What it provides

Host-local defense

Validated policy decisions are enforced through an authoritative nftables ruleset, with local telemetry and operational evidence.

What it does not claim

No hidden proxy role

SysWarden is not an inline HTTP proxy, a traffic sanitizer or a regulatory certification product.

One reviewable host defense layer

01

Authoritative HIPS

Canonical IP, CIDR and service-scoped policy with persistent blocklists, whitelists and bounded SSH exceptions.

02

Host telemetry

Local security telemetry, log analysis and a native TUI without a browser service or an additional listening port.

03

Out-of-band WAAP

Analysis of logs written by supported upstream services, without claiming to proxy or sanitize application traffic.

04

Threat intelligence

Validated external feeds, operator-defined ASN and country controls, and last-known-good publication behavior.

05

Authenticated HA

TLS 1.3, bearer authentication, peer-scoped synchronization, explicit ownership and migration fences.

06

Auditable delivery

Checksummed native packages, signed update metadata, SBOMs and release qualification evidence.

Fast decisions, bounded authority

SysWarden separates observation, decision and enforcement so each security boundary remains visible to operators.

Review the architecture
1

Observe

Collect host and supported upstream log signals without inserting SysWarden into the application data path.

2

Decide

Canonicalize inputs, apply signatures and operator policy, and reject ambiguous state before publication.

3

Enforce

Publish validated decisions through authoritative nftables rules while preserving explicit firewall ownership.

Native packages for AMD64 Linux

Operational procedures, package verification and lifecycle guidance are centralized in the project wiki.

Supported SysWarden operating systems and packages
FamilySupported linesPackage
Debian13DEB
Ubuntu24.04, 26.04DEB
Fedora44RPM
AlmaLinux9, 10RPM
Alpine Linux3.22, 3.24APK

ARM64/AArch64 and FreeBSD packages are not part of the supported release matrix.

Installation and operations

Use the maintained wiki procedures

Verify a package, install, configure, upgrade, roll back, audit or uninstall SysWarden with the release-bound documentation.

Open deployment documentation

Security claims stay bounded

Policy

Fail-closed boundaries

Ambiguous configuration, identity, feed or HA state is rejected before security policy is published.

Supply chain

Verifiable artifacts

Release assets expose checksums, signed update metadata, software bills of materials and qualification outputs.

Operations

Explicit ownership

Existing firewall service ownership is preserved, and host mutation remains reviewable through native package lifecycles.

Help SysWarden keep moving

Infrastructure, multi-distribution qualification and security review require continuous work. Community support helps fund the next verified improvements.

Support SysWarden on Ko-fi

Source code and project documentation are available on GitHub.