FerroSentry: Active Server Defense & Continuous Posture Auditing
Ultralightweight host security and EDR in Rust. Continuous auditd monitoring, SSH brute-force mitigation, dynamic nftables/UFW firewall management, and File Integrity Monitoring (FIM) with a standalone TUI.
Engineered for Peak Reliability
Crafted in native Rust with least-privilege principles, ultra-low memory footprint, and zero unneeded overhead on your hosts.
Active Detection & Response
Intercepts suspicious behavior, anomalous shell spawns, and privilege escalation using Linux auditd.
Network Shield & Firewall
Applies automated blacklists for malicious IPs and syncs boundary rules without restarting network services.
Interactive Security TUI
Inspect live security events, active alerts, and firewall rules directly in your terminal via 'ferrosentry tui'.
File Integrity Monitoring (FIM)
Instant cryptographic auditing of unauthorized modifications in /etc, /bin, and critical system paths.
How It Works Under the Hood
Built from the ground up for maximum resilience, zero unneeded host resource consumption, and robust automated operations.
Auditd Netlink Socket
Continuous kernel security event monitoring for SSH logins, privilege escalation, and file drift.
Heuristic Defense Engine
Sub-50ms brute-force anomaly detection and CIS Benchmark security posture compliance checks.
Kernel Firewall Insertion
Direct atomic nftables & UFW rule enforcement to ban malicious actors without service reloads.
Conduit Event Dispatch
Outbound gRPC event pipeline notifying SecuryBlack Cloud incident dashboard in real time.
Why Upgrade from Fragile Bash Scripts?
A side-by-side technical breakdown comparing FerroSentry against traditional custom scripts and heavyweight legacy alternatives.
| Capability | FerroSentry | Bash / Shell Scripts | Legacy Alternatives |
|---|---|---|---|
| Memory Consumption | < 15 MB RAM (Rust) | Fail2ban + UFW scripts | 600 MB – 1.5 GB (CrowdStrike/Wazuh) |
| Brute-force Blocking | < 50 ms (Native nftables) | 5–30 s (Python log parsing) | Variable (Heavy agents) |
| Interactive Console (TUI) | Native ('ferrosentry tui') | No | No (Web panel only) |
| Continuous FIM Auditing | Kernel inotify / fanotify | Periodic cron diff | Batch scanning |
| SecuryBlack Cloud Integration | Native (gRPC Tunnel + EDR) | None | None |