Back to projects
23 Mar 2019
1 min read

TheMirador

Python Based Linux IDS PoC

TheMirador is an watchtower for linux systems, it monitors user configured system file integrity and access, sudo command access, ssh logins, iptables changes, it emails the admin on any of this events using postfix and also logs the incidents and will also dump system memory contents to a file for forensics. Made a systemd service for the same.