awesome-repositories.com
Blog
MCP
awesome-repositories.com

Discover the best open-source repositories with AI-powered search.

ExploreCurated searchesOpen-source alternativesSelf-hosted softwareBlogSitemap
ProjectMCP serverAboutHow we rankPress
LegalPrivacyTerms
© 2026 Bringes Technology SRL·VAT RO45896025·hello@awesome-repositories.com
·
fail2ban avatar

fail2ban/fail2ban

0
View on GitHub↗
17,993 stars·1,478 forks·Python·13 viewswww.fail2ban.org↗

Fail2ban

Fail2ban is an intrusion prevention system that monitors system log files to detect malicious activity and automatically enforce security policies. By parsing log data in real time, the tool identifies patterns of unauthorized access or repeated authentication failures and responds by dynamically updating network access control lists to restrict offending sources.

The software functions as a firewall automation tool that maintains stateful tracking of suspicious behavior across various network services. It utilizes a regex-driven pattern matching engine to identify specific attack signatures, allowing administrators to define custom filter criteria for different services. This approach enables the automated mitigation of brute force attacks and credential stuffing attempts by temporarily banning hosts that exceed configurable security thresholds.

The system architecture decouples event detection from the execution of blocking commands, ensuring that security responses do not impact overall system performance. It employs a firewall-abstraction layer to translate these security bans into system-level commands, supporting integration with various packet filtering tools to harden Linux server environments.

Features

  • Intrusion Prevention Systems - Monitors system logs for malicious activity and automatically updates firewall rules to block offending IP addresses.
  • Firewall Management - Automates firewall management by dynamically banning hosts that exceed defined thresholds for suspicious behavior.
  • Brute Force Protections - Automatically blocks IP addresses showing repeated failed login attempts to prevent brute force and credential stuffing.
  • IP Address Filters - Updates firewall rules to block network traffic from specific IP addresses that exceed suspicious behavior thresholds.
  • Intrusion Detection Systems - Enables the definition of custom log parsing patterns to detect and respond to unique attack signatures.
  • Network Access Controls - Manages temporary firewall bans for malicious hosts to protect the network perimeter and maintain system integrity.
  • Network Access Restrictions - Restricts network access for specific IP addresses by updating firewall rules after detecting repeated authentication failures.
  • Log-Based Scanners - Parses system logs using regular expressions to detect unauthorized access attempts and enforce automated security policies.
  • Monitoring and Process Control - Daemon to block hosts based on repeated authentication failures.
  • Security And Hardening - Daemon for banning hosts based on authentication failures.
  • Security And Privacy - Daemon for banning hosts based on authentication errors.
  • Security Auditing - Automated log analysis to ban IPs exhibiting malicious behavior.
  • Security & Privacy - Intrusion prevention software.
  • Linux Security Hardening - Hardens Linux server environments by dynamically updating firewall rules based on real-time log analysis.
  • Log Analysis - Parses system log files in real time to identify patterns of malicious activity using regular expressions.
  • Custom Pattern Matchers - Allows administrators to define custom regular expression patterns to identify and respond to specific attack signatures.
  • State Management - Maintains stateful tracking of failed authentication attempts per host to enforce security thresholds.
  • Security Configurations - Provides configuration settings to define security thresholds and ban durations for individual services.
  • Abstraction Layers - Provides an abstraction layer to translate security bans into system-level commands for various packet filtering tools.
  • File System Monitors - Parses system log files in real time to detect unauthorized access attempts and maintain system security.
  • Regex Parsers - Uses configurable regular expressions to extract attack signatures and authentication failures from log streams.
  • System Logging - Collects and monitors system logs to identify patterns of malicious activity and repeated failed login attempts.

Star history

Star history chart for fail2ban/fail2banStar history chart for fail2ban/fail2ban

AI search

Explore more awesome repositories

Describe what you need in plain English — the AI ranks thousands of curated open-source projects by relevance.

Start searching with AI

Frequently asked questions

What does fail2ban/fail2ban do?

Fail2ban is an intrusion prevention system that monitors system log files to detect malicious activity and automatically enforce security policies. By parsing log data in real time, the tool identifies patterns of unauthorized access or repeated authentication failures and responds by dynamically updating network access control lists to restrict offending sources.

What are the main features of fail2ban/fail2ban?

The main features of fail2ban/fail2ban are: Intrusion Prevention Systems, Firewall Management, Brute Force Protections, IP Address Filters, Intrusion Detection Systems, Network Access Controls, Network Access Restrictions, Log-Based Scanners.

What are some open-source alternatives to fail2ban/fail2ban?

Open-source alternatives to fail2ban/fail2ban include: crowdsecurity/crowdsec — CrowdSec is a collaborative, distributed security engine designed for threat detection and infrastructure protection.… wazuh/wazuh — Wazuh is an integrated security platform that combines endpoint detection and response, security information and event… opnsense/core — This project is the core management framework for a security appliance, providing the primary infrastructure for… oisf/suricata — Suricata is an open-source network intrusion detection and prevention engine that analyzes live network traffic in… sbilly/awesome-security — This project is a comprehensive, curated directory of cybersecurity resources, software, and documentation designed to… hashicorp/vault — Vault is a centralized secrets management platform designed to secure, store, and control access to sensitive…

Open-source alternatives to Fail2ban

Similar open-source projects, ranked by how many features they share with Fail2ban.
  • crowdsecurity/crowdseccrowdsecurity avatar

    crowdsecurity/crowdsec

    12,574View on GitHub↗

    CrowdSec is a collaborative, distributed security engine designed for threat detection and infrastructure protection. It functions as an intrusion detection system that parses logs and network traffic to identify malicious patterns, utilizing a bucket-based threshold detection model to aggregate events and trigger alerts. The platform is built on a modular architecture that includes a centralized local API server for managing security signals and a relational database for persistent storage of remediation decisions. What distinguishes the project is its decoupled enforcement model, which offl

    Goattacks-preventiondetectionids
    View on GitHub↗12,574
  • wazuh/wazuhwazuh avatar

    wazuh/wazuh

    14,779View on GitHub↗

    Wazuh is an integrated security platform that combines endpoint detection and response, security information and event management, and cloud workload protection. It functions as a centralized system for collecting telemetry, aggregating logs, and correlating events across distributed infrastructure to maintain security and integrity. The platform distinguishes itself through its active response orchestration, which allows for the automated execution of scripts on remote endpoints to neutralize threats in real time. It provides deep visibility into system activity through file integrity monito

    Ccloud-securitycomplianceconfiguration-assessement
    View on GitHub↗14,779
  • opnsense/coreopnsense avatar

    opnsense/core

    4,493View on GitHub↗

    This project is the core management framework for a security appliance, providing the primary infrastructure for firewall management, network intrusion prevention, and high-availability networking. It serves as the centralized system for controlling network security policies, filtering traffic, and administering a security appliance dashboard. The system is distinguished by its high-availability capabilities, which include synchronizing configurations and connection state tables across redundant nodes to enable automatic hardware failover. It also features a modular plugin architecture for ex

    PHPapibsdcaptive-portal
    View on GitHub↗4,493
  • oisf/suricataOISF avatar

    OISF/suricata

    6,008View on GitHub↗

    Suricata is an open-source network intrusion detection and prevention engine that analyzes live network traffic in real-time to identify and alert on malicious activity. It operates as a rule-based threat detection system, matching traffic against user-defined signatures to detect known attack patterns and policy violations, and can be placed inline to actively block malicious packets before they reach their target. The engine inspects a wide range of application-layer protocols including HTTP, DNS, TLS, SMB, and MQTT, and supports high-performance packet capture through specialized hardware a

    Ccybersecurityidsintrusion-detection-system
    View on GitHub↗6,008
See all 30 alternatives to Fail2ban→