Detect repeated abuse
Use supported service logs and plugin reports to identify login attacks and suspicious requests. Keep the events that explain the detection.
Witen Warden for Linux
Warden detects repeated SSH login failures and abuse in supported web-server logs. It can block the source IP through your firewall, record the reason, and remove the block when it expires.
Version 0.1.19. Requires administrator access to the host. Free downloads; hosted plans are optional.
Packages for Debian, Ubuntu, RPM-based distributions, and Alpine. Portable glibc and musl builds are available for Gentoo and other Linux systems.
Choosing a server security tool? Compare Warden with Fail2Ban.
Use supported service logs and plugin reports to identify login attacks and suspicious requests. Keep the events that explain the detection.
Inspect active blocks, allow trusted addresses, and remove a block locally. You keep access to these controls if the Witen website is unavailable.
Choose thresholds and ban durations for your services. Blocks expire automatically instead of accumulating indefinitely.
Connect your account for blocklist updates and reports across enrolled systems. WordPress and Matomo plugins can also send application events through Warden’s local socket.
The supplied configuration uses nftables. To evaluate without changing firewall rules, set backend = "null" in the [jail] section before starting Warden. Check the detected services and trusted addresses before switching to nftables.
warden validate --config /etc/witen/warden.toml.