Get the latest tech news
Show HN: TheProtector – Linux Bash script for the paranoid admin on a budget
Linux Bash Script for the Paranoid Admin on a Budget - real-time monitoring and active threat response - IHATEGIVINGAUSERNAME/theProtector
Automatically blocks malicious IP addresses Terminates suspicious processes immediately Quarantines detected malware with forensic preservation Restores modified critical system files from backups Kills reverse shell connections and C2 communications bash (4.0 or higher) curl or wget awk, grep, sed netstat or ss iptables cron (for scheduled scans) Unauthorized privilege escalation New user account creation Critical file modifications Suspicious process execution Persistence mechanism installation Configuration tampering
Or read this on Hacker News