SysSpectogram v0.2.0 - hybrid host ML + perimeter + Telegram
Tag: v0.2.0
Title: SysSpectogram v0.2.0 — hybrid host ML + perimeter + Telegram
--- paste below into GitHub Release description ---
SysSpectogram v0.2.0
First public release of a Linux hybrid IDS: host behavioral ML (CNN + Isolation Forest) plus perimeter/egress guard and a Telegram SOAR-lite control plane.
Repo: https://github.com/lifeqsoll/SysSpectogram
Highlights
- Host pipeline:
collect→build-dataset→train→monitor/analyze - Perimeter: SSH auth fail/brute, inbound scan heuristics, egress denylist, suspicious DNS
guard: perimeter + host ML + Telegram slash/inline (confirm before ban/kill/lockdown)- Dual alert panel (metrics heatmap + top-PID CPU)
- OSINT recon (PTR/enrich/DNS/CT); nmap only via lab allowlist
- Local load sims + intrusion lab scripts (localhost only)
- Safer defaults: recon/nmap off, TG simulate/collect off, nft unban by handle, temporal val split, artifact checksums, webhook HMAC
Install
git clone https://github.com/lifeqsoll/SysSpectogram.git
cd SysSpectogram
python -m venv .venv && source .venv/bin/activate
pip install torch --index-url https://download.pytorch.org/whl/cpu
pip install -e ".[dev]"
cp .env.example .env # optional TelegramQuick start
# train your own artifacts (not shipped)
python -m sysspectogram collect --out data/normal.csv --duration 1800
# …sim + anomaly collect…
python -m sysspectogram build-dataset --normal data/normal.csv --anomaly data/anomaly.csv --out dataset/real
python -m sysspectogram train --dataset dataset/real --out artifacts/real
# live (dry-run safe)
python -m sysspectogram guard --model artifacts/real --telegram --dry-runDocs
Safety
- Linux only. No Win/Mac.
- Destructive TG actions require confirm; ban/kill need real privileges (omit
--dry-run). - Do not aim sims/nmap at third-party networks.
- Model quality = your labeled data; no pretrained weights in the repo.
Known limitations
- Live nft without dry-run needs suitable privileges/systemd caps
- Retrain to get
checksums.sha256on artifacts - Not antivirus / full NIDS / SIEM