Skip to content
All security projects
Security projectDemo readyIDS · Rule engine

Custom IDS Script

Lightweight rule-based Linux intrusion detection — evaluates YAML rules against auth.log, syslog, and shell history to emit terminal, Markdown, and JSON alerts.

Loads YAML rule files describing detection patterns (failed logins, suspicious commands, new user creation, sudo abuse) and applies them to log lines, producing actionable alerts with timestamps and recommended response actions. Targeted at small Linux servers, kiosks, and lab environments.

PythonCLIYAML rulesauth.log

Catalog entry only — a full write-up lands closer to release.

Related across catalogs

Want a heads-up when Custom IDS Script releases?

Subscribe via blog