Skip to content

SysSpectogram v0.2.0 - hybrid host ML + perimeter + Telegram

Choose a tag to compare

@lifeqsoll lifeqsoll released this 24 Sep 18:19
· 18 commits to main since this release

Tag: v0.2.0
Title: SysSpectogram v0.2.0 — hybrid host ML + perimeter + Telegram

--- paste below into GitHub Release description ---

SysSpectogram v0.2.0

First public release of a Linux hybrid IDS: host behavioral ML (CNN + Isolation Forest) plus perimeter/egress guard and a Telegram SOAR-lite control plane.

Repo: https://github.com/lifeqsoll/SysSpectogram

Highlights

  • Host pipeline: collect → build-dataset → train → monitor / analyze
  • Perimeter: SSH auth fail/brute, inbound scan heuristics, egress denylist, suspicious DNS
  • guard: perimeter + host ML + Telegram slash/inline (confirm before ban/kill/lockdown)
  • Dual alert panel (metrics heatmap + top-PID CPU)
  • OSINT recon (PTR/enrich/DNS/CT); nmap only via lab allowlist
  • Local load sims + intrusion lab scripts (localhost only)
  • Safer defaults: recon/nmap off, TG simulate/collect off, nft unban by handle, temporal val split, artifact checksums, webhook HMAC

Install

git clone https://github.com/lifeqsoll/SysSpectogram.git
cd SysSpectogram
python -m venv .venv && source .venv/bin/activate
pip install torch --index-url https://download.pytorch.org/whl/cpu
pip install -e ".[dev]"
cp .env.example .env   # optional Telegram

Quick start

# train your own artifacts (not shipped)
python -m sysspectogram collect --out data/normal.csv --duration 1800
# …sim + anomaly collect…
python -m sysspectogram build-dataset --normal data/normal.csv --anomaly data/anomaly.csv --out dataset/real
python -m sysspectogram train --dataset dataset/real --out artifacts/real

# live (dry-run safe)
python -m sysspectogram guard --model artifacts/real --telegram --dry-run

Docs

Safety

  • Linux only. No Win/Mac.
  • Destructive TG actions require confirm; ban/kill need real privileges (omit --dry-run).
  • Do not aim sims/nmap at third-party networks.
  • Model quality = your labeled data; no pretrained weights in the repo.

Known limitations

  • Live nft without dry-run needs suitable privileges/systemd caps
  • Retrain to get checksums.sha256 on artifacts
  • Not antivirus / full NIDS / SIEM