Patriot-Linux – Host IDS For Desktop Users
Patriot Linux is a HIDS for desktop users who wants real time graphical alerts when something suspicious happens
Patriot detect:
1- Suspicious process running
![Patriot-Linux - Host IDS For Desktop Users 1 Patriot](https://www.redpacketsecurity.com/wp-content/uploads/2021/02/Patriot-Linux_1_patriot3.png)
2- New process starting TCP/IP Connection
![Patriot-Linux - Host IDS For Desktop Users 2 Patriot](https://www.redpacketsecurity.com/wp-content/uploads/2021/02/Patriot-Linux_2_patriot2.png)
3- Auditd alerts
![Patriot-Linux - Host IDS For Desktop Users 3 Patriot](https://www.redpacketsecurity.com/wp-content/uploads/2021/02/Patriot-Linux_3_patriot1.png)
4- New keyboards plugged
Installation
You need to configure Auditd with this suggested rules https://github.com/Neo23x0/auditd (you can use your own rules and simply modify keywords in the code)
Install xinput (apt install xinput or yum install xorg-x11-server-utils)
And then simply download py files and run python3 patriot.py
Tested in CentOS/Fedora and Debian/Ubuntu
If you like the site, please consider joining the telegram channel or supporting us on Patreon using the button below.