Rust Native · Open Source · Apache 2.0

FerroSentry: Active Server Defense & Continuous Posture Auditing

Ultralightweight host security and EDR in Rust. Continuous auditd monitoring, SSH brute-force mitigation, dynamic nftables/UFW firewall management, and File Integrity Monitoring (FIM) with a standalone TUI.

RAM Footprint
< 15 MB
Zero JVM / Python
Brute-Force Mitigation
< 50 ms
Immediate nftables blocking
FIM Monitoring
Inotify
Real-time kernel events
Compliance
CIS Benchmark
Automated audit
curl -fsSL https://install.ferrosentry.dev | sudo bash
STANDALONE
// Real-Time EDR alerts & kernel audit events
[● MITIGATED] SSH Brute-Force Attack32 ms ago
IP 185.220.101.5 performed 7 failed SSH handshakes.
Action: Added to nftables `@blacklist_ssh` for 86400s (Zero CPU impact).
[● AUDITED] Sudo Privilege Escalation14m ago
User deploy ran `/usr/bin/systemctl reload nginx` via sudo.
<Tab> Navigate<q> Quit TUI
High-Resilience Engineering

Engineered for Peak Reliability

Crafted in native Rust with least-privilege principles, ultra-low memory footprint, and zero unneeded overhead on your hosts.

EDR
Real-time Host EDR

Active Detection & Response

Intercepts suspicious behavior, anomalous shell spawns, and privilege escalation using Linux auditd.

FerroSentry CoreLearn more →
Firewall
nftables / iptables / UFW

Network Shield & Firewall

Applies automated blacklists for malicious IPs and syncs boundary rules without restarting network services.

FerroSentry CoreLearn more →
TUI
Terminal Inspector

Interactive Security TUI

Inspect live security events, active alerts, and firewall rules directly in your terminal via 'ferrosentry tui'.

FerroSentry CoreLearn more →
Integrity
Real-time File Integrity

File Integrity Monitoring (FIM)

Instant cryptographic auditing of unauthorized modifications in /etc, /bin, and critical system paths.

FerroSentry CoreLearn more →
Architecture & Pipeline

How It Works Under the Hood

Built from the ground up for maximum resilience, zero unneeded host resource consumption, and robust automated operations.

STEP 01Kernel Netlink

Auditd Netlink Socket

Continuous kernel security event monitoring for SSH logins, privilege escalation, and file drift.

Verified in runtime
STEP 02Autonomous

Heuristic Defense Engine

Sub-50ms brute-force anomaly detection and CIS Benchmark security posture compliance checks.

Verified in runtime
STEP 03Instant Drop

Kernel Firewall Insertion

Direct atomic nftables & UFW rule enforcement to ban malicious actors without service reloads.

Verified in runtime
STEP 04Zero Inbound Port

Conduit Event Dispatch

Outbound gRPC event pipeline notifying SecuryBlack Cloud incident dashboard in real time.

Verified in runtime
Technical Benchmark

Why Upgrade from Fragile Bash Scripts?

A side-by-side technical breakdown comparing FerroSentry against traditional custom scripts and heavyweight legacy alternatives.

CapabilityFerroSentryBash / Shell ScriptsLegacy Alternatives
Memory Consumption< 15 MB RAM (Rust)Fail2ban + UFW scripts600 MB – 1.5 GB (CrowdStrike/Wazuh)
Brute-force Blocking< 50 ms (Native nftables)5–30 s (Python log parsing)Variable (Heavy agents)
Interactive Console (TUI)Native ('ferrosentry tui')NoNo (Web panel only)
Continuous FIM AuditingKernel inotify / fanotifyPeriodic cron diffBatch scanning
SecuryBlack Cloud IntegrationNative (gRPC Tunnel + EDR)NoneNone
Frequently Asked Questions

Everything You Need to Know

Yes, and much more efficiently. Instead of parsing text log files with regular expressions in Python, FerroSentry hooks into system socket events and enforces nftables drops in nanoseconds.

Get Started with FerroSentry Today

Deploy in under 60 seconds as an autonomous open-source agent or connect with SecuryBlack Cloud for centralized fleet orchestration.