Block abuse without losing the plot.

Witen watches login and request activity, blocks abusive addresses with expiring firewall rules, and keeps the evidence that led to each block.

Start in observe mode. Turn on blocking when the results look right.

Decision applied
dec_7f31a9

Temporary host block

198.51.100.24

Coordinated credential abuse appeared in WordPress, HTTP, and SSH telemetry. Witen promoted a time-bounded block after the evidence crossed policy confidence.

Confidence
94%
Enforced by
nftables
Scope
This host
Expires
18 minutes

Evidence

3 sources
  • WordPress · 14 failed administrator logins
  • Web server · 3 probes for vulnerable PHP paths
  • SSH · 6 authentication failures across 2 hosts

Automatic expiry is active

AllowUndo Explained

What happens on the server

From log line to temporary block

A firewall and a log monitor, tied together with an audit trail.

Read

Warden follows SSH and web logs on the machine you already run.

Score

Repeated failures and probes build a case. One odd request does not become a ban.

Block

When a policy threshold is crossed, Warden adds a narrow nftables rule with an expiry.

Review

See the source events, allow the address, or remove the block from the same host.

Local by default

Your server keeps the controls

Warden can block, explain, expire, and undo decisions without calling home. Connect the portal when you want to compare activity across machines.

Keeps working when the portal is unavailable
Expires blocks instead of leaving permanent surprises
Shows which events produced each decision
Reports whether a rule was applied, failed, or removed

Start with the server you know best

Run Warden in observe mode, compare its decisions with your logs, and enable blocking when you are satisfied with the policy.