Offline Linux Forensics & Integrity Engine
-
Updated
Jun 5, 2026 - Python
Offline Linux Forensics & Integrity Engine
Real-time rule-based Host-Based Intrusion Detection System built in Python. Captures live network packets using Scapy, detects 8 attack types (Port Scan, SYN Flood, ARP Spoofing, DNS Flood and more) using sliding window algorithms, and visualises threats through a SOC-style Tkinter dashboard with SQLite persistence. Runs on Windows and Kali Linux.
Add a description, image, and links to the host-based-ids topic page so that developers can more easily learn about it.
To associate your repository with the host-based-ids topic, visit your repo's landing page and select "manage topics."