Repository files navigation

fail2counter

AI-powered attacker analysis for fail2ban. When fail2ban bans an IP, fail2counter scans the attacker back, identifies their vulnerabilities using AI-selected Metasploit modules, and determines if they are a compromised machine being used as an attack platform.

LEGAL WARNING

Unauthorized computer scanning and exploitation is illegal in most jurisdictions.

By using this software, you acknowledge and accept the following:

United States

  • Computer Fraud and Abuse Act (CFAA), 18 U.S.C. 1030: Unauthorized access to computer systems carries penalties of up to 10 years imprisonment for first offenses and up to 20 years for repeat offenses, plus fines up to $250,000.
  • Electronic Communications Privacy Act (ECPA): Intercepting electronic communications without authorization carries penalties of up to 5 years imprisonment.

European Union

  • EU Directive 2013/40/EU (Attacks against information systems): Illegal access to information systems carries penalties of at least 2 years imprisonment. Using tools for committing such offences carries at least 3 years.
  • GDPR (Regulation 2016/679): Processing personal data (including IP addresses) without lawful basis can result in fines up to EUR 20 million or 4% of annual global turnover.

United Kingdom

  • Computer Misuse Act 1990: Unauthorized access carries up to 2 years imprisonment. Unauthorized access with intent to commit further offences carries up to 5 years. Unauthorized acts impairing computer operation carries up to 10 years.

Other Jurisdictions

Most countries have similar laws criminalizing unauthorized computer access and network scanning. Check your local laws before using this software.

Authorized Use Only

This tool is intended exclusively for:

  • Defensive security on systems you own or are authorized to test
  • Authorized penetration testing with written consent
  • Security research in controlled lab environments
  • Incident response where you have legal authority to investigate

You use this software entirely at your own risk. The authors accept no liability for any legal consequences arising from its use.


How It Works

flowchart TD
A[Attacker hits your server] --> B[fail2ban detects & bans IP]
B --> C["podman exec: push_ip.py <IP>"]
C --> D[Redis queue: banned_ips]
subgraph Container ["Podman Container"]
D --> E[Worker dequeues IP]
E --> F{Host up?}
F -->|No| G[Skip]
F -->|Yes| H["nmap fast scan (top 100 ports)"]
H --> I{Open ports?}
I -->|No| G
I -->|Yes| J["nmap version detection"]
J --> K[Store scan results in PostgreSQL]
K --> L["Claude AI analyzes nmap output"]
L --> M["Filter 2500+ exploits to relevant subset"]
M --> N["Generate Metasploit RC files"]
N --> O["Execute exploits via msfconsole"]
O --> P[Store exploit results in PostgreSQL]
P --> Q{Session opened?}
Q -->|Yes| R[Create abuse notification record]
Q -->|No| S[Log as completed]
R --> T[Send email report]
S --> T
T --> U{30 scans done?}
U -->|Yes| V[Rotate VPN for new exit IP]
U -->|No| E
V --> E
subgraph VPN ["VPN Network Namespace (msf_vpn)"]
H
J
O
end
subgraph Services ["Internal Services"]
D
DB[(PostgreSQL)]
K --> DB
P --> DB
end
end
style VPN fill:#1a1a2e,color:#e0e0e0
style Container fill:#0d1117,color:#e0e0e0
style Services fill:#161b22,color:#e0e0e0
Loading

All scanning and exploit traffic is routed through an OpenVPN tunnel in an isolated network namespace. Your server's real IP is never exposed. The VPN rotates every 30 scans for IP diversity.

Requirements

  • Linux host with podman and fail2ban installed
  • OpenVPN configuration file (.ovpn) from a VPN provider
  • Anthropic API key or Google Vertex AI credentials

Installation

git clone https://github.com/dmzoneill/fail2counter.git
cd fail2counter
sudo ./install.sh

The installer asks for 3 things:

  1. Email address for scan reports
  2. AI provider (Anthropic API key or GCP Vertex AI project)
  3. OpenVPN config file (.ovpn) for scan traffic routing

Everything else is handled automatically:

  • Builds the container image with all dependencies
  • Copies and secures the VPN configuration
  • Creates the systemd service
  • Installs the fail2ban action

Usage

# Start the service
sudo systemctl start fail2counter
# Check status
sudo systemctl status fail2counter
# View logs
sudo podman logs -f fail2counter
# Manually queue an IP for testing
sudo podman exec fail2counter /opt/fail2counter/fail2counter_push_ip.py 1.2.3.4

Fail2ban Integration

Add fail2counter to any jail's action list in /etc/fail2ban/jail.local:

[sshd]enabled = true
action = iptables-multiport[name=sshd, port="ssh"]
fail2counter

Restart fail2ban: sudo systemctl restart fail2ban

Architecture

graph LR
subgraph Host["Host System"]
F2B[fail2ban]
SMTP[Postfix/SMTP]
end
subgraph Pod["Podman Container"]
REDIS[(Redis)]
PG[(PostgreSQL)]
WORKER[Worker Daemon]
MSF[Metasploit]
NMAP[nmap]
AI[Claude AI]
subgraph NS["msf_vpn namespace"]
VPN[OpenVPN Tunnel]
NMAP
MSF
end
end
subgraph Ext["External"]
TARGET[Banned IP]
ANTHROPIC[Anthropic API]
VPNPROV[VPN Provider]
end
F2B -->|"podman exec push_ip.py"| REDIS
REDIS --> WORKER
WORKER --> NMAP
WORKER --> AI
AI --> ANTHROPIC
WORKER --> MSF
WORKER --> PG
WORKER -->|email report| SMTP
NMAP --> VPN
MSF --> VPN
VPN --> VPNPROV
VPNPROV --> TARGET
style NS fill:#1a1a2e,color:#e0e0e0
style Pod fill:#0d1117,color:#e0e0e0
style Host fill:#161b22,color:#e0e0e0
Loading

What's Inside the Container

ComponentPurpose
RedisQueue between fail2ban and the worker
PostgreSQLStores scan results, exploit findings, notifications
Metasploit FrameworkExploit execution engine
nmapNetwork scanning
OpenVPNVPN tunnel in isolated network namespace
Claude AISelects applicable exploits based on scan results

Database Schema

erDiagram
hosts ||--o{ scans : has
scans ||--o{ ports : has
ports ||--o{ services : has
scans ||--o{ exploits : tested_with
hosts ||--o{ exploits : targeted
exploits ||--o{ exploit_results : produces
hosts ||--o{ notifications : generates
exploits ||--o{ notifications : triggers
hosts {
int id PK
varchar ip_address
varchar hostname
timestamp created_at
}
scans {
int id PK
int host_id FK
timestamp scan_time
varchar scan_type
float latency_seconds
float duration_seconds
}
ports {
int id PK
int scan_id FK
int port_number
varchar protocol
varchar state
}
services {
int id PK
int port_id FK
varchar service_name
varchar product
varchar version
boolean is_ssl
}
exploits {
int id PK
int scan_id FK
int host_id FK
varchar module_path
varchar rhosts
int rport
varchar status
}
exploit_results {
int id PK
int exploit_id FK
text output_text
int exit_code
float duration_seconds
}
notifications {
int id PK
int host_id FK
int exploit_id FK
varchar notification_type
varchar status
text message
}
Loading

Configuration

All config lives in /etc/fail2counter/:

FilePurpose
.envMain config (email, AI credentials, SMTP settings)
vpn.ovpnOpenVPN configuration (copied during install)
gcp-credentials.jsonGCP service account key (Vertex AI only)

See .env.example for all available options. To change configuration after install:

sudo nano /etc/fail2counter/.env
sudo systemctl restart fail2counter

Environment Variables

VariableRequiredDefaultDescription
NOTIFICATION_EMAILYes-Email for scan reports
ANTHROPIC_API_KEYOne of-Direct Anthropic API key
ANTHROPIC_VERTEX_PROJECT_IDthese-GCP project for Vertex AI
ANTHROPIC_VERTEX_REGIONNous-east5GCP region
GOOGLE_APPLICATION_CREDENTIALSNo-Path to GCP key JSON
NOTIFICATION_FROMNofail2counter@localhostEmail sender address
SMTP_HOSTNolocalhostSMTP server
SMTP_PORTNo25SMTP port
VPN_ROTATE_INTERVALNo30Rotate VPN every N scans

License

MIT

About

Fail2ban log analyzer and intrusion attempt counter

Topics

Resources

Stars

0 stars

Watchers

0 watching

Forks

Releases

Packages

Used by

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Add copy buttons to all
 blocks\n(function() {\n function addCopyButtons() {\n document.querySelectorAll('pre code').forEach(function(codeBlock) {\n if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;\n codeBlock.parentElement.setAttribute('data-copy-added', 'true');\n \n var btn = document.createElement('button');\n btn.textContent = 'Copy';\n btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';\n btn.onmouseover = function() { this.style.opacity = '1'; };\n btn.onmouseout = function() { this.style.opacity = '0.7'; };\n btn.onclick = function() {\n navigator.clipboard.writeText(codeBlock.textContent).then(function() {\n btn.textContent = 'Copied!';\n setTimeout(function() { btn.textContent = 'Copy'; }, 1500);\n });\n };\n codeBlock.parentElement.style.position = 'relative';\n codeBlock.parentElement.appendChild(btn);\n });\n }\n \n addCopyButtons();\n \n // Re-run on dynamic content\n var observer = new MutationObserver(addCopyButtons);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Add Copy Buttons to Code Blocks");
}
} catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
})();
(function(){
try {
var __m = "github.com";
var __re = new RegExp('^' + "github\\.com" + '
Skip to content

Repository files navigation

fail2counter

AI-powered attacker analysis for fail2ban. When fail2ban bans an IP, fail2counter scans the attacker back, identifies their vulnerabilities using AI-selected Metasploit modules, and determines if they are a compromised machine being used as an attack platform.

LEGAL WARNING

Unauthorized computer scanning and exploitation is illegal in most jurisdictions.

By using this software, you acknowledge and accept the following:

United States

  • Computer Fraud and Abuse Act (CFAA), 18 U.S.C. 1030: Unauthorized access to computer systems carries penalties of up to 10 years imprisonment for first offenses and up to 20 years for repeat offenses, plus fines up to $250,000.
  • Electronic Communications Privacy Act (ECPA): Intercepting electronic communications without authorization carries penalties of up to 5 years imprisonment.

European Union

  • EU Directive 2013/40/EU (Attacks against information systems): Illegal access to information systems carries penalties of at least 2 years imprisonment. Using tools for committing such offences carries at least 3 years.
  • GDPR (Regulation 2016/679): Processing personal data (including IP addresses) without lawful basis can result in fines up to EUR 20 million or 4% of annual global turnover.

United Kingdom

  • Computer Misuse Act 1990: Unauthorized access carries up to 2 years imprisonment. Unauthorized access with intent to commit further offences carries up to 5 years. Unauthorized acts impairing computer operation carries up to 10 years.

Other Jurisdictions

Most countries have similar laws criminalizing unauthorized computer access and network scanning. Check your local laws before using this software.

Authorized Use Only

This tool is intended exclusively for:

  • Defensive security on systems you own or are authorized to test
  • Authorized penetration testing with written consent
  • Security research in controlled lab environments
  • Incident response where you have legal authority to investigate

You use this software entirely at your own risk. The authors accept no liability for any legal consequences arising from its use.


How It Works

flowchart TD
A[Attacker hits your server] --> B[fail2ban detects & bans IP]
B --> C["podman exec: push_ip.py <IP>"]
C --> D[Redis queue: banned_ips]
subgraph Container ["Podman Container"]
D --> E[Worker dequeues IP]
E --> F{Host up?}
F -->|No| G[Skip]
F -->|Yes| H["nmap fast scan (top 100 ports)"]
H --> I{Open ports?}
I -->|No| G
I -->|Yes| J["nmap version detection"]
J --> K[Store scan results in PostgreSQL]
K --> L["Claude AI analyzes nmap output"]
L --> M["Filter 2500+ exploits to relevant subset"]
M --> N["Generate Metasploit RC files"]
N --> O["Execute exploits via msfconsole"]
O --> P[Store exploit results in PostgreSQL]
P --> Q{Session opened?}
Q -->|Yes| R[Create abuse notification record]
Q -->|No| S[Log as completed]
R --> T[Send email report]
S --> T
T --> U{30 scans done?}
U -->|Yes| V[Rotate VPN for new exit IP]
U -->|No| E
V --> E
subgraph VPN ["VPN Network Namespace (msf_vpn)"]
H
J
O
end
subgraph Services ["Internal Services"]
D
DB[(PostgreSQL)]
K --> DB
P --> DB
end
end
style VPN fill:#1a1a2e,color:#e0e0e0
style Container fill:#0d1117,color:#e0e0e0
style Services fill:#161b22,color:#e0e0e0
Loading

All scanning and exploit traffic is routed through an OpenVPN tunnel in an isolated network namespace. Your server's real IP is never exposed. The VPN rotates every 30 scans for IP diversity.

Requirements

  • Linux host with podman and fail2ban installed
  • OpenVPN configuration file (.ovpn) from a VPN provider
  • Anthropic API key or Google Vertex AI credentials

Installation

git clone https://github.com/dmzoneill/fail2counter.git
cd fail2counter
sudo ./install.sh

The installer asks for 3 things:

  1. Email address for scan reports
  2. AI provider (Anthropic API key or GCP Vertex AI project)
  3. OpenVPN config file (.ovpn) for scan traffic routing

Everything else is handled automatically:

  • Builds the container image with all dependencies
  • Copies and secures the VPN configuration
  • Creates the systemd service
  • Installs the fail2ban action

Usage

# Start the service
sudo systemctl start fail2counter
# Check status
sudo systemctl status fail2counter
# View logs
sudo podman logs -f fail2counter
# Manually queue an IP for testing
sudo podman exec fail2counter /opt/fail2counter/fail2counter_push_ip.py 1.2.3.4

Fail2ban Integration

Add fail2counter to any jail's action list in /etc/fail2ban/jail.local:

[sshd]enabled = true
action = iptables-multiport[name=sshd, port="ssh"]
fail2counter

Restart fail2ban: sudo systemctl restart fail2ban

Architecture

graph LR
subgraph Host["Host System"]
F2B[fail2ban]
SMTP[Postfix/SMTP]
end
subgraph Pod["Podman Container"]
REDIS[(Redis)]
PG[(PostgreSQL)]
WORKER[Worker Daemon]
MSF[Metasploit]
NMAP[nmap]
AI[Claude AI]
subgraph NS["msf_vpn namespace"]
VPN[OpenVPN Tunnel]
NMAP
MSF
end
end
subgraph Ext["External"]
TARGET[Banned IP]
ANTHROPIC[Anthropic API]
VPNPROV[VPN Provider]
end
F2B -->|"podman exec push_ip.py"| REDIS
REDIS --> WORKER
WORKER --> NMAP
WORKER --> AI
AI --> ANTHROPIC
WORKER --> MSF
WORKER --> PG
WORKER -->|email report| SMTP
NMAP --> VPN
MSF --> VPN
VPN --> VPNPROV
VPNPROV --> TARGET
style NS fill:#1a1a2e,color:#e0e0e0
style Pod fill:#0d1117,color:#e0e0e0
style Host fill:#161b22,color:#e0e0e0
Loading

What's Inside the Container

ComponentPurpose
RedisQueue between fail2ban and the worker
PostgreSQLStores scan results, exploit findings, notifications
Metasploit FrameworkExploit execution engine
nmapNetwork scanning
OpenVPNVPN tunnel in isolated network namespace
Claude AISelects applicable exploits based on scan results

Database Schema

erDiagram
hosts ||--o{ scans : has
scans ||--o{ ports : has
ports ||--o{ services : has
scans ||--o{ exploits : tested_with
hosts ||--o{ exploits : targeted
exploits ||--o{ exploit_results : produces
hosts ||--o{ notifications : generates
exploits ||--o{ notifications : triggers
hosts {
int id PK
varchar ip_address
varchar hostname
timestamp created_at
}
scans {
int id PK
int host_id FK
timestamp scan_time
varchar scan_type
float latency_seconds
float duration_seconds
}
ports {
int id PK
int scan_id FK
int port_number
varchar protocol
varchar state
}
services {
int id PK
int port_id FK
varchar service_name
varchar product
varchar version
boolean is_ssl
}
exploits {
int id PK
int scan_id FK
int host_id FK
varchar module_path
varchar rhosts
int rport
varchar status
}
exploit_results {
int id PK
int exploit_id FK
text output_text
int exit_code
float duration_seconds
}
notifications {
int id PK
int host_id FK
int exploit_id FK
varchar notification_type
varchar status
text message
}
Loading

Configuration

All config lives in /etc/fail2counter/:

FilePurpose
.envMain config (email, AI credentials, SMTP settings)
vpn.ovpnOpenVPN configuration (copied during install)
gcp-credentials.jsonGCP service account key (Vertex AI only)

See .env.example for all available options. To change configuration after install:

sudo nano /etc/fail2counter/.env
sudo systemctl restart fail2counter

Environment Variables

VariableRequiredDefaultDescription
NOTIFICATION_EMAILYes-Email for scan reports
ANTHROPIC_API_KEYOne of-Direct Anthropic API key
ANTHROPIC_VERTEX_PROJECT_IDthese-GCP project for Vertex AI
ANTHROPIC_VERTEX_REGIONNous-east5GCP region
GOOGLE_APPLICATION_CREDENTIALSNo-Path to GCP key JSON
NOTIFICATION_FROMNofail2counter@localhostEmail sender address
SMTP_HOSTNolocalhostSMTP server
SMTP_PORTNo25SMTP port
VPN_ROTATE_INTERVALNo30Rotate VPN every N scans

License

MIT

About

Fail2ban log analyzer and intrusion attempt counter

Topics

Resources

Stars

0 stars

Watchers

0 watching

Forks

Releases

Packages

Used by

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Force GitHub README to respect dark mode\n(function() {\n var style = document.createElement('style');\n style.textContent = '\n .markdown-body {\n color-scheme: dark light;\n }\n .markdown-body pre { background: #161b22 !important; }\n .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; }\n .markdown-body table th, .markdown-body table td { border-color: #30363d !important; }\n .markdown-body img { background: #0d1117; }\n .markdown-body blockquote { border-left-color: #8b949e; }\n .markdown-body hr { border-color: #30363d; }\n ';\n document.head.appendChild(style);\n})();", "GitHub Dark Mode README Fix"); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Repository files navigation

fail2counter

AI-powered attacker analysis for fail2ban. When fail2ban bans an IP, fail2counter scans the attacker back, identifies their vulnerabilities using AI-selected Metasploit modules, and determines if they are a compromised machine being used as an attack platform.

LEGAL WARNING

Unauthorized computer scanning and exploitation is illegal in most jurisdictions.

By using this software, you acknowledge and accept the following:

United States

  • Computer Fraud and Abuse Act (CFAA), 18 U.S.C. 1030: Unauthorized access to computer systems carries penalties of up to 10 years imprisonment for first offenses and up to 20 years for repeat offenses, plus fines up to $250,000.
  • Electronic Communications Privacy Act (ECPA): Intercepting electronic communications without authorization carries penalties of up to 5 years imprisonment.

European Union

  • EU Directive 2013/40/EU (Attacks against information systems): Illegal access to information systems carries penalties of at least 2 years imprisonment. Using tools for committing such offences carries at least 3 years.
  • GDPR (Regulation 2016/679): Processing personal data (including IP addresses) without lawful basis can result in fines up to EUR 20 million or 4% of annual global turnover.

United Kingdom

  • Computer Misuse Act 1990: Unauthorized access carries up to 2 years imprisonment. Unauthorized access with intent to commit further offences carries up to 5 years. Unauthorized acts impairing computer operation carries up to 10 years.

Other Jurisdictions

Most countries have similar laws criminalizing unauthorized computer access and network scanning. Check your local laws before using this software.

Authorized Use Only

This tool is intended exclusively for:

  • Defensive security on systems you own or are authorized to test
  • Authorized penetration testing with written consent
  • Security research in controlled lab environments
  • Incident response where you have legal authority to investigate

You use this software entirely at your own risk. The authors accept no liability for any legal consequences arising from its use.


How It Works

flowchart TD
A[Attacker hits your server] --> B[fail2ban detects & bans IP]
B --> C["podman exec: push_ip.py <IP>"]
C --> D[Redis queue: banned_ips]
subgraph Container ["Podman Container"]
D --> E[Worker dequeues IP]
E --> F{Host up?}
F -->|No| G[Skip]
F -->|Yes| H["nmap fast scan (top 100 ports)"]
H --> I{Open ports?}
I -->|No| G
I -->|Yes| J["nmap version detection"]
J --> K[Store scan results in PostgreSQL]
K --> L["Claude AI analyzes nmap output"]
L --> M["Filter 2500+ exploits to relevant subset"]
M --> N["Generate Metasploit RC files"]
N --> O["Execute exploits via msfconsole"]
O --> P[Store exploit results in PostgreSQL]
P --> Q{Session opened?}
Q -->|Yes| R[Create abuse notification record]
Q -->|No| S[Log as completed]
R --> T[Send email report]
S --> T
T --> U{30 scans done?}
U -->|Yes| V[Rotate VPN for new exit IP]
U -->|No| E
V --> E
subgraph VPN ["VPN Network Namespace (msf_vpn)"]
H
J
O
end
subgraph Services ["Internal Services"]
D
DB[(PostgreSQL)]
K --> DB
P --> DB
end
end
style VPN fill:#1a1a2e,color:#e0e0e0
style Container fill:#0d1117,color:#e0e0e0
style Services fill:#161b22,color:#e0e0e0
Loading

All scanning and exploit traffic is routed through an OpenVPN tunnel in an isolated network namespace. Your server's real IP is never exposed. The VPN rotates every 30 scans for IP diversity.

Requirements

  • Linux host with podman and fail2ban installed
  • OpenVPN configuration file (.ovpn) from a VPN provider
  • Anthropic API key or Google Vertex AI credentials

Installation

git clone https://github.com/dmzoneill/fail2counter.git
cd fail2counter
sudo ./install.sh

The installer asks for 3 things:

  1. Email address for scan reports
  2. AI provider (Anthropic API key or GCP Vertex AI project)
  3. OpenVPN config file (.ovpn) for scan traffic routing

Everything else is handled automatically:

  • Builds the container image with all dependencies
  • Copies and secures the VPN configuration
  • Creates the systemd service
  • Installs the fail2ban action

Usage

# Start the service
sudo systemctl start fail2counter
# Check status
sudo systemctl status fail2counter
# View logs
sudo podman logs -f fail2counter
# Manually queue an IP for testing
sudo podman exec fail2counter /opt/fail2counter/fail2counter_push_ip.py 1.2.3.4

Fail2ban Integration

Add fail2counter to any jail's action list in /etc/fail2ban/jail.local:

[sshd]enabled = true
action = iptables-multiport[name=sshd, port="ssh"]
fail2counter

Restart fail2ban: sudo systemctl restart fail2ban

Architecture

graph LR
subgraph Host["Host System"]
F2B[fail2ban]
SMTP[Postfix/SMTP]
end
subgraph Pod["Podman Container"]
REDIS[(Redis)]
PG[(PostgreSQL)]
WORKER[Worker Daemon]
MSF[Metasploit]
NMAP[nmap]
AI[Claude AI]
subgraph NS["msf_vpn namespace"]
VPN[OpenVPN Tunnel]
NMAP
MSF
end
end
subgraph Ext["External"]
TARGET[Banned IP]
ANTHROPIC[Anthropic API]
VPNPROV[VPN Provider]
end
F2B -->|"podman exec push_ip.py"| REDIS
REDIS --> WORKER
WORKER --> NMAP
WORKER --> AI
AI --> ANTHROPIC
WORKER --> MSF
WORKER --> PG
WORKER -->|email report| SMTP
NMAP --> VPN
MSF --> VPN
VPN --> VPNPROV
VPNPROV --> TARGET
style NS fill:#1a1a2e,color:#e0e0e0
style Pod fill:#0d1117,color:#e0e0e0
style Host fill:#161b22,color:#e0e0e0
Loading

What's Inside the Container

ComponentPurpose
RedisQueue between fail2ban and the worker
PostgreSQLStores scan results, exploit findings, notifications
Metasploit FrameworkExploit execution engine
nmapNetwork scanning
OpenVPNVPN tunnel in isolated network namespace
Claude AISelects applicable exploits based on scan results

Database Schema

erDiagram
hosts ||--o{ scans : has
scans ||--o{ ports : has
ports ||--o{ services : has
scans ||--o{ exploits : tested_with
hosts ||--o{ exploits : targeted
exploits ||--o{ exploit_results : produces
hosts ||--o{ notifications : generates
exploits ||--o{ notifications : triggers
hosts {
int id PK
varchar ip_address
varchar hostname
timestamp created_at
}
scans {
int id PK
int host_id FK
timestamp scan_time
varchar scan_type
float latency_seconds
float duration_seconds
}
ports {
int id PK
int scan_id FK
int port_number
varchar protocol
varchar state
}
services {
int id PK
int port_id FK
varchar service_name
varchar product
varchar version
boolean is_ssl
}
exploits {
int id PK
int scan_id FK
int host_id FK
varchar module_path
varchar rhosts
int rport
varchar status
}
exploit_results {
int id PK
int exploit_id FK
text output_text
int exit_code
float duration_seconds
}
notifications {
int id PK
int host_id FK
int exploit_id FK
varchar notification_type
varchar status
text message
}
Loading

Configuration

All config lives in /etc/fail2counter/:

FilePurpose
.envMain config (email, AI credentials, SMTP settings)
vpn.ovpnOpenVPN configuration (copied during install)
gcp-credentials.jsonGCP service account key (Vertex AI only)

See .env.example for all available options. To change configuration after install:

sudo nano /etc/fail2counter/.env
sudo systemctl restart fail2counter

Environment Variables

VariableRequiredDefaultDescription
NOTIFICATION_EMAILYes-Email for scan reports
ANTHROPIC_API_KEYOne of-Direct Anthropic API key
ANTHROPIC_VERTEX_PROJECT_IDthese-GCP project for Vertex AI
ANTHROPIC_VERTEX_REGIONNous-east5GCP region
GOOGLE_APPLICATION_CREDENTIALSNo-Path to GCP key JSON
NOTIFICATION_FROMNofail2counter@localhostEmail sender address
SMTP_HOSTNolocalhostSMTP server
SMTP_PORTNo25SMTP port
VPN_ROTATE_INTERVALNo30Rotate VPN every N scans

License

MIT

About

Fail2ban log analyzer and intrusion attempt counter

Topics

Resources

Stars

0 stars

Watchers

0 watching

Forks

Releases

Packages

Used by

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Highlight search terms from Google/DuckDuckGo/Bing referrer\n(function() {\n var ref = document.referrer;\n var terms = [];\n \n if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) {\n var url = new URL(ref);\n var q = url.searchParams.get('q') || url.searchParams.get('p');\n if (q) {\n terms = q.split(/\\s+/).filter(function(t) { return t.length > 2; });\n }\n }\n \n if (terms.length === 0) return;\n \n var style = document.createElement('style');\n style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }';\n document.head.appendChild(style);\n \n function highlight(node) {\n if (node.nodeType === 3) { // text node\n var text = node.textContent;\n var found = false;\n terms.forEach(function(term) {\n var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\\]\\\\]/g, '\\\\') + ')', 'gi');\n if (regex.test(text)) {\n found = true;\n var frag = document.createDocumentFragment();\n var parts = text.split(regex);\n parts.forEach(function(part, i) {\n if (i % 2 === 0) {\n frag.appendChild(document.createTextNode(part));\n } else {\n var span = document.createElement('span');\n span.className = 'userscript-highlight';\n span.textContent = part;\n frag.appendChild(span);\n }\n });\n node.parentNode.replaceChild(frag, node);\n }\n });\n } else if (node.nodeType === 1 && node.childNodes) { // element\n var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT'];\n if (!skipTags.includes(node.tagName)) {\n Array.from(node.childNodes).forEach(highlight);\n }\n }\n }\n \n highlight(document.body);\n \n // Re-highlight on dynamic content\n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1 || node.nodeType === 3) highlight(node);\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Highlight Search Terms"); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Repository files navigation

fail2counter

AI-powered attacker analysis for fail2ban. When fail2ban bans an IP, fail2counter scans the attacker back, identifies their vulnerabilities using AI-selected Metasploit modules, and determines if they are a compromised machine being used as an attack platform.

LEGAL WARNING

Unauthorized computer scanning and exploitation is illegal in most jurisdictions.

By using this software, you acknowledge and accept the following:

United States

  • Computer Fraud and Abuse Act (CFAA), 18 U.S.C. 1030: Unauthorized access to computer systems carries penalties of up to 10 years imprisonment for first offenses and up to 20 years for repeat offenses, plus fines up to $250,000.
  • Electronic Communications Privacy Act (ECPA): Intercepting electronic communications without authorization carries penalties of up to 5 years imprisonment.

European Union

  • EU Directive 2013/40/EU (Attacks against information systems): Illegal access to information systems carries penalties of at least 2 years imprisonment. Using tools for committing such offences carries at least 3 years.
  • GDPR (Regulation 2016/679): Processing personal data (including IP addresses) without lawful basis can result in fines up to EUR 20 million or 4% of annual global turnover.

United Kingdom

  • Computer Misuse Act 1990: Unauthorized access carries up to 2 years imprisonment. Unauthorized access with intent to commit further offences carries up to 5 years. Unauthorized acts impairing computer operation carries up to 10 years.

Other Jurisdictions

Most countries have similar laws criminalizing unauthorized computer access and network scanning. Check your local laws before using this software.

Authorized Use Only

This tool is intended exclusively for:

  • Defensive security on systems you own or are authorized to test
  • Authorized penetration testing with written consent
  • Security research in controlled lab environments
  • Incident response where you have legal authority to investigate

You use this software entirely at your own risk. The authors accept no liability for any legal consequences arising from its use.


How It Works

flowchart TD
A[Attacker hits your server] --> B[fail2ban detects & bans IP]
B --> C["podman exec: push_ip.py <IP>"]
C --> D[Redis queue: banned_ips]
subgraph Container ["Podman Container"]
D --> E[Worker dequeues IP]
E --> F{Host up?}
F -->|No| G[Skip]
F -->|Yes| H["nmap fast scan (top 100 ports)"]
H --> I{Open ports?}
I -->|No| G
I -->|Yes| J["nmap version detection"]
J --> K[Store scan results in PostgreSQL]
K --> L["Claude AI analyzes nmap output"]
L --> M["Filter 2500+ exploits to relevant subset"]
M --> N["Generate Metasploit RC files"]
N --> O["Execute exploits via msfconsole"]
O --> P[Store exploit results in PostgreSQL]
P --> Q{Session opened?}
Q -->|Yes| R[Create abuse notification record]
Q -->|No| S[Log as completed]
R --> T[Send email report]
S --> T
T --> U{30 scans done?}
U -->|Yes| V[Rotate VPN for new exit IP]
U -->|No| E
V --> E
subgraph VPN ["VPN Network Namespace (msf_vpn)"]
H
J
O
end
subgraph Services ["Internal Services"]
D
DB[(PostgreSQL)]
K --> DB
P --> DB
end
end
style VPN fill:#1a1a2e,color:#e0e0e0
style Container fill:#0d1117,color:#e0e0e0
style Services fill:#161b22,color:#e0e0e0
Loading

All scanning and exploit traffic is routed through an OpenVPN tunnel in an isolated network namespace. Your server's real IP is never exposed. The VPN rotates every 30 scans for IP diversity.

Requirements

  • Linux host with podman and fail2ban installed
  • OpenVPN configuration file (.ovpn) from a VPN provider
  • Anthropic API key or Google Vertex AI credentials

Installation

git clone https://github.com/dmzoneill/fail2counter.git
cd fail2counter
sudo ./install.sh

The installer asks for 3 things:

  1. Email address for scan reports
  2. AI provider (Anthropic API key or GCP Vertex AI project)
  3. OpenVPN config file (.ovpn) for scan traffic routing

Everything else is handled automatically:

  • Builds the container image with all dependencies
  • Copies and secures the VPN configuration
  • Creates the systemd service
  • Installs the fail2ban action

Usage

# Start the service
sudo systemctl start fail2counter
# Check status
sudo systemctl status fail2counter
# View logs
sudo podman logs -f fail2counter
# Manually queue an IP for testing
sudo podman exec fail2counter /opt/fail2counter/fail2counter_push_ip.py 1.2.3.4

Fail2ban Integration

Add fail2counter to any jail's action list in /etc/fail2ban/jail.local:

[sshd]enabled = true
action = iptables-multiport[name=sshd, port="ssh"]
fail2counter

Restart fail2ban: sudo systemctl restart fail2ban

Architecture

graph LR
subgraph Host["Host System"]
F2B[fail2ban]
SMTP[Postfix/SMTP]
end
subgraph Pod["Podman Container"]
REDIS[(Redis)]
PG[(PostgreSQL)]
WORKER[Worker Daemon]
MSF[Metasploit]
NMAP[nmap]
AI[Claude AI]
subgraph NS["msf_vpn namespace"]
VPN[OpenVPN Tunnel]
NMAP
MSF
end
end
subgraph Ext["External"]
TARGET[Banned IP]
ANTHROPIC[Anthropic API]
VPNPROV[VPN Provider]
end
F2B -->|"podman exec push_ip.py"| REDIS
REDIS --> WORKER
WORKER --> NMAP
WORKER --> AI
AI --> ANTHROPIC
WORKER --> MSF
WORKER --> PG
WORKER -->|email report| SMTP
NMAP --> VPN
MSF --> VPN
VPN --> VPNPROV
VPNPROV --> TARGET
style NS fill:#1a1a2e,color:#e0e0e0
style Pod fill:#0d1117,color:#e0e0e0
style Host fill:#161b22,color:#e0e0e0
Loading

What's Inside the Container

ComponentPurpose
RedisQueue between fail2ban and the worker
PostgreSQLStores scan results, exploit findings, notifications
Metasploit FrameworkExploit execution engine
nmapNetwork scanning
OpenVPNVPN tunnel in isolated network namespace
Claude AISelects applicable exploits based on scan results

Database Schema

erDiagram
hosts ||--o{ scans : has
scans ||--o{ ports : has
ports ||--o{ services : has
scans ||--o{ exploits : tested_with
hosts ||--o{ exploits : targeted
exploits ||--o{ exploit_results : produces
hosts ||--o{ notifications : generates
exploits ||--o{ notifications : triggers
hosts {
int id PK
varchar ip_address
varchar hostname
timestamp created_at
}
scans {
int id PK
int host_id FK
timestamp scan_time
varchar scan_type
float latency_seconds
float duration_seconds
}
ports {
int id PK
int scan_id FK
int port_number
varchar protocol
varchar state
}
services {
int id PK
int port_id FK
varchar service_name
varchar product
varchar version
boolean is_ssl
}
exploits {
int id PK
int scan_id FK
int host_id FK
varchar module_path
varchar rhosts
int rport
varchar status
}
exploit_results {
int id PK
int exploit_id FK
text output_text
int exit_code
float duration_seconds
}
notifications {
int id PK
int host_id FK
int exploit_id FK
varchar notification_type
varchar status
text message
}
Loading

Configuration

All config lives in /etc/fail2counter/:

FilePurpose
.envMain config (email, AI credentials, SMTP settings)
vpn.ovpnOpenVPN configuration (copied during install)
gcp-credentials.jsonGCP service account key (Vertex AI only)

See .env.example for all available options. To change configuration after install:

sudo nano /etc/fail2counter/.env
sudo systemctl restart fail2counter

Environment Variables

VariableRequiredDefaultDescription
NOTIFICATION_EMAILYes-Email for scan reports
ANTHROPIC_API_KEYOne of-Direct Anthropic API key
ANTHROPIC_VERTEX_PROJECT_IDthese-GCP project for Vertex AI
ANTHROPIC_VERTEX_REGIONNous-east5GCP region
GOOGLE_APPLICATION_CREDENTIALSNo-Path to GCP key JSON
NOTIFICATION_FROMNofail2counter@localhostEmail sender address
SMTP_HOSTNolocalhostSMTP server
SMTP_PORTNo25SMTP port
VPN_ROTATE_INTERVALNo30Rotate VPN every N scans

License

MIT

About

Fail2ban log analyzer and intrusion attempt counter

Topics

Resources

Stars

0 stars

Watchers

0 watching

Forks

Releases

Packages

Used by

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Strip utm_, fbclid, gclid, etc. from all links on page\n(function() {\n var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content',\n 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid',\n 'ref', 'ref_src', 'source', 'medium', 'campaign'];\n \n function cleanUrl(url) {\n try {\n var u = new URL(url, window.location.origin);\n var changed = false;\n trackingParams.forEach(function(p) {\n if (u.searchParams.has(p)) {\n u.searchParams.delete(p);\n changed = true;\n }\n });\n return changed ? u.toString() : url;\n } catch (e) {\n return url;\n }\n }\n \n function cleanLinks() {\n document.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n \n cleanLinks();\n \n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1) {\n if (node.tagName === 'A') cleanLinks();\n node.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Remove Tracking Parameters from Links"); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + '
Skip to content

Repository files navigation

fail2counter

AI-powered attacker analysis for fail2ban. When fail2ban bans an IP, fail2counter scans the attacker back, identifies their vulnerabilities using AI-selected Metasploit modules, and determines if they are a compromised machine being used as an attack platform.

LEGAL WARNING

Unauthorized computer scanning and exploitation is illegal in most jurisdictions.

By using this software, you acknowledge and accept the following:

United States

  • Computer Fraud and Abuse Act (CFAA), 18 U.S.C. 1030: Unauthorized access to computer systems carries penalties of up to 10 years imprisonment for first offenses and up to 20 years for repeat offenses, plus fines up to $250,000.
  • Electronic Communications Privacy Act (ECPA): Intercepting electronic communications without authorization carries penalties of up to 5 years imprisonment.

European Union

  • EU Directive 2013/40/EU (Attacks against information systems): Illegal access to information systems carries penalties of at least 2 years imprisonment. Using tools for committing such offences carries at least 3 years.
  • GDPR (Regulation 2016/679): Processing personal data (including IP addresses) without lawful basis can result in fines up to EUR 20 million or 4% of annual global turnover.

United Kingdom

  • Computer Misuse Act 1990: Unauthorized access carries up to 2 years imprisonment. Unauthorized access with intent to commit further offences carries up to 5 years. Unauthorized acts impairing computer operation carries up to 10 years.

Other Jurisdictions

Most countries have similar laws criminalizing unauthorized computer access and network scanning. Check your local laws before using this software.

Authorized Use Only

This tool is intended exclusively for:

  • Defensive security on systems you own or are authorized to test
  • Authorized penetration testing with written consent
  • Security research in controlled lab environments
  • Incident response where you have legal authority to investigate

You use this software entirely at your own risk. The authors accept no liability for any legal consequences arising from its use.


How It Works

flowchart TD
A[Attacker hits your server] --> B[fail2ban detects & bans IP]
B --> C["podman exec: push_ip.py <IP>"]
C --> D[Redis queue: banned_ips]
subgraph Container ["Podman Container"]
D --> E[Worker dequeues IP]
E --> F{Host up?}
F -->|No| G[Skip]
F -->|Yes| H["nmap fast scan (top 100 ports)"]
H --> I{Open ports?}
I -->|No| G
I -->|Yes| J["nmap version detection"]
J --> K[Store scan results in PostgreSQL]
K --> L["Claude AI analyzes nmap output"]
L --> M["Filter 2500+ exploits to relevant subset"]
M --> N["Generate Metasploit RC files"]
N --> O["Execute exploits via msfconsole"]
O --> P[Store exploit results in PostgreSQL]
P --> Q{Session opened?}
Q -->|Yes| R[Create abuse notification record]
Q -->|No| S[Log as completed]
R --> T[Send email report]
S --> T
T --> U{30 scans done?}
U -->|Yes| V[Rotate VPN for new exit IP]
U -->|No| E
V --> E
subgraph VPN ["VPN Network Namespace (msf_vpn)"]
H
J
O
end
subgraph Services ["Internal Services"]
D
DB[(PostgreSQL)]
K --> DB
P --> DB
end
end
style VPN fill:#1a1a2e,color:#e0e0e0
style Container fill:#0d1117,color:#e0e0e0
style Services fill:#161b22,color:#e0e0e0
Loading

All scanning and exploit traffic is routed through an OpenVPN tunnel in an isolated network namespace. Your server's real IP is never exposed. The VPN rotates every 30 scans for IP diversity.

Requirements

  • Linux host with podman and fail2ban installed
  • OpenVPN configuration file (.ovpn) from a VPN provider
  • Anthropic API key or Google Vertex AI credentials

Installation

git clone https://github.com/dmzoneill/fail2counter.git
cd fail2counter
sudo ./install.sh

The installer asks for 3 things:

  1. Email address for scan reports
  2. AI provider (Anthropic API key or GCP Vertex AI project)
  3. OpenVPN config file (.ovpn) for scan traffic routing

Everything else is handled automatically:

  • Builds the container image with all dependencies
  • Copies and secures the VPN configuration
  • Creates the systemd service
  • Installs the fail2ban action

Usage

# Start the service
sudo systemctl start fail2counter
# Check status
sudo systemctl status fail2counter
# View logs
sudo podman logs -f fail2counter
# Manually queue an IP for testing
sudo podman exec fail2counter /opt/fail2counter/fail2counter_push_ip.py 1.2.3.4

Fail2ban Integration

Add fail2counter to any jail's action list in /etc/fail2ban/jail.local:

[sshd]enabled = true
action = iptables-multiport[name=sshd, port="ssh"]
fail2counter

Restart fail2ban: sudo systemctl restart fail2ban

Architecture

graph LR
subgraph Host["Host System"]
F2B[fail2ban]
SMTP[Postfix/SMTP]
end
subgraph Pod["Podman Container"]
REDIS[(Redis)]
PG[(PostgreSQL)]
WORKER[Worker Daemon]
MSF[Metasploit]
NMAP[nmap]
AI[Claude AI]
subgraph NS["msf_vpn namespace"]
VPN[OpenVPN Tunnel]
NMAP
MSF
end
end
subgraph Ext["External"]
TARGET[Banned IP]
ANTHROPIC[Anthropic API]
VPNPROV[VPN Provider]
end
F2B -->|"podman exec push_ip.py"| REDIS
REDIS --> WORKER
WORKER --> NMAP
WORKER --> AI
AI --> ANTHROPIC
WORKER --> MSF
WORKER --> PG
WORKER -->|email report| SMTP
NMAP --> VPN
MSF --> VPN
VPN --> VPNPROV
VPNPROV --> TARGET
style NS fill:#1a1a2e,color:#e0e0e0
style Pod fill:#0d1117,color:#e0e0e0
style Host fill:#161b22,color:#e0e0e0
Loading

What's Inside the Container

ComponentPurpose
RedisQueue between fail2ban and the worker
PostgreSQLStores scan results, exploit findings, notifications
Metasploit FrameworkExploit execution engine
nmapNetwork scanning
OpenVPNVPN tunnel in isolated network namespace
Claude AISelects applicable exploits based on scan results

Database Schema

erDiagram
hosts ||--o{ scans : has
scans ||--o{ ports : has
ports ||--o{ services : has
scans ||--o{ exploits : tested_with
hosts ||--o{ exploits : targeted
exploits ||--o{ exploit_results : produces
hosts ||--o{ notifications : generates
exploits ||--o{ notifications : triggers
hosts {
int id PK
varchar ip_address
varchar hostname
timestamp created_at
}
scans {
int id PK
int host_id FK
timestamp scan_time
varchar scan_type
float latency_seconds
float duration_seconds
}
ports {
int id PK
int scan_id FK
int port_number
varchar protocol
varchar state
}
services {
int id PK
int port_id FK
varchar service_name
varchar product
varchar version
boolean is_ssl
}
exploits {
int id PK
int scan_id FK
int host_id FK
varchar module_path
varchar rhosts
int rport
varchar status
}
exploit_results {
int id PK
int exploit_id FK
text output_text
int exit_code
float duration_seconds
}
notifications {
int id PK
int host_id FK
int exploit_id FK
varchar notification_type
varchar status
text message
}
Loading

Configuration

All config lives in /etc/fail2counter/:

FilePurpose
.envMain config (email, AI credentials, SMTP settings)
vpn.ovpnOpenVPN configuration (copied during install)
gcp-credentials.jsonGCP service account key (Vertex AI only)

See .env.example for all available options. To change configuration after install:

sudo nano /etc/fail2counter/.env
sudo systemctl restart fail2counter

Environment Variables

VariableRequiredDefaultDescription
NOTIFICATION_EMAILYes-Email for scan reports
ANTHROPIC_API_KEYOne of-Direct Anthropic API key
ANTHROPIC_VERTEX_PROJECT_IDthese-GCP project for Vertex AI
ANTHROPIC_VERTEX_REGIONNous-east5GCP region
GOOGLE_APPLICATION_CREDENTIALSNo-Path to GCP key JSON
NOTIFICATION_FROMNofail2counter@localhostEmail sender address
SMTP_HOSTNolocalhostSMTP server
SMTP_PORTNo25SMTP port
VPN_ROTATE_INTERVALNo30Rotate VPN every N scans

License

MIT

About

Fail2ban log analyzer and intrusion attempt counter

Topics

Resources

Stars

0 stars

Watchers

0 watching

Forks

Releases

Packages

Used by

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Auto-enable theater mode on YouTube\n(function() {\n function tryTheater() {\n var btn = document.querySelector('button[aria-label=\"Theater mode\"], ytd-player #player button[title=\"Theater mode\"]');\n if (btn && !btn.classList.contains('activated')) {\n btn.click();\n }\n }\n \n // Try immediately\n tryTheater();\n \n // Try after navigation (SPA)\n var lastUrl = location.href;\n setInterval(function() {\n if (location.href !== lastUrl) {\n lastUrl = location.href;\n setTimeout(tryTheater, 500);\n }\n }, 1000);\n \n // Also try on player load\n var observer = new MutationObserver(tryTheater);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "YouTube Theater Mode Default"); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Repository files navigation

fail2counter

AI-powered attacker analysis for fail2ban. When fail2ban bans an IP, fail2counter scans the attacker back, identifies their vulnerabilities using AI-selected Metasploit modules, and determines if they are a compromised machine being used as an attack platform.

LEGAL WARNING

Unauthorized computer scanning and exploitation is illegal in most jurisdictions.

By using this software, you acknowledge and accept the following:

United States

  • Computer Fraud and Abuse Act (CFAA), 18 U.S.C. 1030: Unauthorized access to computer systems carries penalties of up to 10 years imprisonment for first offenses and up to 20 years for repeat offenses, plus fines up to $250,000.
  • Electronic Communications Privacy Act (ECPA): Intercepting electronic communications without authorization carries penalties of up to 5 years imprisonment.

European Union

  • EU Directive 2013/40/EU (Attacks against information systems): Illegal access to information systems carries penalties of at least 2 years imprisonment. Using tools for committing such offences carries at least 3 years.
  • GDPR (Regulation 2016/679): Processing personal data (including IP addresses) without lawful basis can result in fines up to EUR 20 million or 4% of annual global turnover.

United Kingdom

  • Computer Misuse Act 1990: Unauthorized access carries up to 2 years imprisonment. Unauthorized access with intent to commit further offences carries up to 5 years. Unauthorized acts impairing computer operation carries up to 10 years.

Other Jurisdictions

Most countries have similar laws criminalizing unauthorized computer access and network scanning. Check your local laws before using this software.

Authorized Use Only

This tool is intended exclusively for:

  • Defensive security on systems you own or are authorized to test
  • Authorized penetration testing with written consent
  • Security research in controlled lab environments
  • Incident response where you have legal authority to investigate

You use this software entirely at your own risk. The authors accept no liability for any legal consequences arising from its use.


How It Works

flowchart TD
A[Attacker hits your server] --> B[fail2ban detects & bans IP]
B --> C["podman exec: push_ip.py <IP>"]
C --> D[Redis queue: banned_ips]
subgraph Container ["Podman Container"]
D --> E[Worker dequeues IP]
E --> F{Host up?}
F -->|No| G[Skip]
F -->|Yes| H["nmap fast scan (top 100 ports)"]
H --> I{Open ports?}
I -->|No| G
I -->|Yes| J["nmap version detection"]
J --> K[Store scan results in PostgreSQL]
K --> L["Claude AI analyzes nmap output"]
L --> M["Filter 2500+ exploits to relevant subset"]
M --> N["Generate Metasploit RC files"]
N --> O["Execute exploits via msfconsole"]
O --> P[Store exploit results in PostgreSQL]
P --> Q{Session opened?}
Q -->|Yes| R[Create abuse notification record]
Q -->|No| S[Log as completed]
R --> T[Send email report]
S --> T
T --> U{30 scans done?}
U -->|Yes| V[Rotate VPN for new exit IP]
U -->|No| E
V --> E
subgraph VPN ["VPN Network Namespace (msf_vpn)"]
H
J
O
end
subgraph Services ["Internal Services"]
D
DB[(PostgreSQL)]
K --> DB
P --> DB
end
end
style VPN fill:#1a1a2e,color:#e0e0e0
style Container fill:#0d1117,color:#e0e0e0
style Services fill:#161b22,color:#e0e0e0
Loading

All scanning and exploit traffic is routed through an OpenVPN tunnel in an isolated network namespace. Your server's real IP is never exposed. The VPN rotates every 30 scans for IP diversity.

Requirements

  • Linux host with podman and fail2ban installed
  • OpenVPN configuration file (.ovpn) from a VPN provider
  • Anthropic API key or Google Vertex AI credentials

Installation

git clone https://github.com/dmzoneill/fail2counter.git
cd fail2counter
sudo ./install.sh

The installer asks for 3 things:

  1. Email address for scan reports
  2. AI provider (Anthropic API key or GCP Vertex AI project)
  3. OpenVPN config file (.ovpn) for scan traffic routing

Everything else is handled automatically:

  • Builds the container image with all dependencies
  • Copies and secures the VPN configuration
  • Creates the systemd service
  • Installs the fail2ban action

Usage

# Start the service
sudo systemctl start fail2counter
# Check status
sudo systemctl status fail2counter
# View logs
sudo podman logs -f fail2counter
# Manually queue an IP for testing
sudo podman exec fail2counter /opt/fail2counter/fail2counter_push_ip.py 1.2.3.4

Fail2ban Integration

Add fail2counter to any jail's action list in /etc/fail2ban/jail.local:

[sshd]enabled = true
action = iptables-multiport[name=sshd, port="ssh"]
fail2counter

Restart fail2ban: sudo systemctl restart fail2ban

Architecture

graph LR
subgraph Host["Host System"]
F2B[fail2ban]
SMTP[Postfix/SMTP]
end
subgraph Pod["Podman Container"]
REDIS[(Redis)]
PG[(PostgreSQL)]
WORKER[Worker Daemon]
MSF[Metasploit]
NMAP[nmap]
AI[Claude AI]
subgraph NS["msf_vpn namespace"]
VPN[OpenVPN Tunnel]
NMAP
MSF
end
end
subgraph Ext["External"]
TARGET[Banned IP]
ANTHROPIC[Anthropic API]
VPNPROV[VPN Provider]
end
F2B -->|"podman exec push_ip.py"| REDIS
REDIS --> WORKER
WORKER --> NMAP
WORKER --> AI
AI --> ANTHROPIC
WORKER --> MSF
WORKER --> PG
WORKER -->|email report| SMTP
NMAP --> VPN
MSF --> VPN
VPN --> VPNPROV
VPNPROV --> TARGET
style NS fill:#1a1a2e,color:#e0e0e0
style Pod fill:#0d1117,color:#e0e0e0
style Host fill:#161b22,color:#e0e0e0
Loading

What's Inside the Container

ComponentPurpose
RedisQueue between fail2ban and the worker
PostgreSQLStores scan results, exploit findings, notifications
Metasploit FrameworkExploit execution engine
nmapNetwork scanning
OpenVPNVPN tunnel in isolated network namespace
Claude AISelects applicable exploits based on scan results

Database Schema

erDiagram
hosts ||--o{ scans : has
scans ||--o{ ports : has
ports ||--o{ services : has
scans ||--o{ exploits : tested_with
hosts ||--o{ exploits : targeted
exploits ||--o{ exploit_results : produces
hosts ||--o{ notifications : generates
exploits ||--o{ notifications : triggers
hosts {
int id PK
varchar ip_address
varchar hostname
timestamp created_at
}
scans {
int id PK
int host_id FK
timestamp scan_time
varchar scan_type
float latency_seconds
float duration_seconds
}
ports {
int id PK
int scan_id FK
int port_number
varchar protocol
varchar state
}
services {
int id PK
int port_id FK
varchar service_name
varchar product
varchar version
boolean is_ssl
}
exploits {
int id PK
int scan_id FK
int host_id FK
varchar module_path
varchar rhosts
int rport
varchar status
}
exploit_results {
int id PK
int exploit_id FK
text output_text
int exit_code
float duration_seconds
}
notifications {
int id PK
int host_id FK
int exploit_id FK
varchar notification_type
varchar status
text message
}
Loading

Configuration

All config lives in /etc/fail2counter/:

FilePurpose
.envMain config (email, AI credentials, SMTP settings)
vpn.ovpnOpenVPN configuration (copied during install)
gcp-credentials.jsonGCP service account key (Vertex AI only)

See .env.example for all available options. To change configuration after install:

sudo nano /etc/fail2counter/.env
sudo systemctl restart fail2counter

Environment Variables

VariableRequiredDefaultDescription
NOTIFICATION_EMAILYes-Email for scan reports
ANTHROPIC_API_KEYOne of-Direct Anthropic API key
ANTHROPIC_VERTEX_PROJECT_IDthese-GCP project for Vertex AI
ANTHROPIC_VERTEX_REGIONNous-east5GCP region
GOOGLE_APPLICATION_CREDENTIALSNo-Path to GCP key JSON
NOTIFICATION_FROMNofail2counter@localhostEmail sender address
SMTP_HOSTNolocalhostSMTP server
SMTP_PORTNo25SMTP port
VPN_ROTATE_INTERVALNo30Rotate VPN every N scans

License

MIT

About

Fail2ban log analyzer and intrusion attempt counter

Topics

Resources

Stars

0 stars

Watchers

0 watching

Forks

Releases

Packages

Used by

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Remove or un-stick sticky/fixed headers that block content\n(function() {\n function unstick() {\n document.querySelectorAll('header, nav, [role=\"banner\"], .header, .navbar, .sticky, .fixed-top, [style*=\"position: fixed\"], [style*=\"position:sticky\"]').forEach(function(el) {\n if (el.style.position === 'fixed' || el.style.position === 'sticky' || \n getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') {\n el.style.position = 'static';\n el.style.top = 'auto';\n el.style.zIndex = 'auto';\n }\n });\n }\n \n unstick();\n \n var observer = new MutationObserver(unstick);\n observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] });\n})();", "Kill Sticky Headers"); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Repository files navigation

fail2counter

AI-powered attacker analysis for fail2ban. When fail2ban bans an IP, fail2counter scans the attacker back, identifies their vulnerabilities using AI-selected Metasploit modules, and determines if they are a compromised machine being used as an attack platform.

LEGAL WARNING

Unauthorized computer scanning and exploitation is illegal in most jurisdictions.

By using this software, you acknowledge and accept the following:

United States

  • Computer Fraud and Abuse Act (CFAA), 18 U.S.C. 1030: Unauthorized access to computer systems carries penalties of up to 10 years imprisonment for first offenses and up to 20 years for repeat offenses, plus fines up to $250,000.
  • Electronic Communications Privacy Act (ECPA): Intercepting electronic communications without authorization carries penalties of up to 5 years imprisonment.

European Union

  • EU Directive 2013/40/EU (Attacks against information systems): Illegal access to information systems carries penalties of at least 2 years imprisonment. Using tools for committing such offences carries at least 3 years.
  • GDPR (Regulation 2016/679): Processing personal data (including IP addresses) without lawful basis can result in fines up to EUR 20 million or 4% of annual global turnover.

United Kingdom

  • Computer Misuse Act 1990: Unauthorized access carries up to 2 years imprisonment. Unauthorized access with intent to commit further offences carries up to 5 years. Unauthorized acts impairing computer operation carries up to 10 years.

Other Jurisdictions

Most countries have similar laws criminalizing unauthorized computer access and network scanning. Check your local laws before using this software.

Authorized Use Only

This tool is intended exclusively for:

  • Defensive security on systems you own or are authorized to test
  • Authorized penetration testing with written consent
  • Security research in controlled lab environments
  • Incident response where you have legal authority to investigate

You use this software entirely at your own risk. The authors accept no liability for any legal consequences arising from its use.


How It Works

flowchart TD
A[Attacker hits your server] --> B[fail2ban detects & bans IP]
B --> C["podman exec: push_ip.py <IP>"]
C --> D[Redis queue: banned_ips]
subgraph Container ["Podman Container"]
D --> E[Worker dequeues IP]
E --> F{Host up?}
F -->|No| G[Skip]
F -->|Yes| H["nmap fast scan (top 100 ports)"]
H --> I{Open ports?}
I -->|No| G
I -->|Yes| J["nmap version detection"]
J --> K[Store scan results in PostgreSQL]
K --> L["Claude AI analyzes nmap output"]
L --> M["Filter 2500+ exploits to relevant subset"]
M --> N["Generate Metasploit RC files"]
N --> O["Execute exploits via msfconsole"]
O --> P[Store exploit results in PostgreSQL]
P --> Q{Session opened?}
Q -->|Yes| R[Create abuse notification record]
Q -->|No| S[Log as completed]
R --> T[Send email report]
S --> T
T --> U{30 scans done?}
U -->|Yes| V[Rotate VPN for new exit IP]
U -->|No| E
V --> E
subgraph VPN ["VPN Network Namespace (msf_vpn)"]
H
J
O
end
subgraph Services ["Internal Services"]
D
DB[(PostgreSQL)]
K --> DB
P --> DB
end
end
style VPN fill:#1a1a2e,color:#e0e0e0
style Container fill:#0d1117,color:#e0e0e0
style Services fill:#161b22,color:#e0e0e0
Loading

All scanning and exploit traffic is routed through an OpenVPN tunnel in an isolated network namespace. Your server's real IP is never exposed. The VPN rotates every 30 scans for IP diversity.

Requirements

  • Linux host with podman and fail2ban installed
  • OpenVPN configuration file (.ovpn) from a VPN provider
  • Anthropic API key or Google Vertex AI credentials

Installation

git clone https://github.com/dmzoneill/fail2counter.git
cd fail2counter
sudo ./install.sh

The installer asks for 3 things:

  1. Email address for scan reports
  2. AI provider (Anthropic API key or GCP Vertex AI project)
  3. OpenVPN config file (.ovpn) for scan traffic routing

Everything else is handled automatically:

  • Builds the container image with all dependencies
  • Copies and secures the VPN configuration
  • Creates the systemd service
  • Installs the fail2ban action

Usage

# Start the service
sudo systemctl start fail2counter
# Check status
sudo systemctl status fail2counter
# View logs
sudo podman logs -f fail2counter
# Manually queue an IP for testing
sudo podman exec fail2counter /opt/fail2counter/fail2counter_push_ip.py 1.2.3.4

Fail2ban Integration

Add fail2counter to any jail's action list in /etc/fail2ban/jail.local:

[sshd]enabled = true
action = iptables-multiport[name=sshd, port="ssh"]
fail2counter

Restart fail2ban: sudo systemctl restart fail2ban

Architecture

graph LR
subgraph Host["Host System"]
F2B[fail2ban]
SMTP[Postfix/SMTP]
end
subgraph Pod["Podman Container"]
REDIS[(Redis)]
PG[(PostgreSQL)]
WORKER[Worker Daemon]
MSF[Metasploit]
NMAP[nmap]
AI[Claude AI]
subgraph NS["msf_vpn namespace"]
VPN[OpenVPN Tunnel]
NMAP
MSF
end
end
subgraph Ext["External"]
TARGET[Banned IP]
ANTHROPIC[Anthropic API]
VPNPROV[VPN Provider]
end
F2B -->|"podman exec push_ip.py"| REDIS
REDIS --> WORKER
WORKER --> NMAP
WORKER --> AI
AI --> ANTHROPIC
WORKER --> MSF
WORKER --> PG
WORKER -->|email report| SMTP
NMAP --> VPN
MSF --> VPN
VPN --> VPNPROV
VPNPROV --> TARGET
style NS fill:#1a1a2e,color:#e0e0e0
style Pod fill:#0d1117,color:#e0e0e0
style Host fill:#161b22,color:#e0e0e0
Loading

What's Inside the Container

ComponentPurpose
RedisQueue between fail2ban and the worker
PostgreSQLStores scan results, exploit findings, notifications
Metasploit FrameworkExploit execution engine
nmapNetwork scanning
OpenVPNVPN tunnel in isolated network namespace
Claude AISelects applicable exploits based on scan results

Database Schema

erDiagram
hosts ||--o{ scans : has
scans ||--o{ ports : has
ports ||--o{ services : has
scans ||--o{ exploits : tested_with
hosts ||--o{ exploits : targeted
exploits ||--o{ exploit_results : produces
hosts ||--o{ notifications : generates
exploits ||--o{ notifications : triggers
hosts {
int id PK
varchar ip_address
varchar hostname
timestamp created_at
}
scans {
int id PK
int host_id FK
timestamp scan_time
varchar scan_type
float latency_seconds
float duration_seconds
}
ports {
int id PK
int scan_id FK
int port_number
varchar protocol
varchar state
}
services {
int id PK
int port_id FK
varchar service_name
varchar product
varchar version
boolean is_ssl
}
exploits {
int id PK
int scan_id FK
int host_id FK
varchar module_path
varchar rhosts
int rport
varchar status
}
exploit_results {
int id PK
int exploit_id FK
text output_text
int exit_code
float duration_seconds
}
notifications {
int id PK
int host_id FK
int exploit_id FK
varchar notification_type
varchar status
text message
}
Loading

Configuration

All config lives in /etc/fail2counter/:

FilePurpose
.envMain config (email, AI credentials, SMTP settings)
vpn.ovpnOpenVPN configuration (copied during install)
gcp-credentials.jsonGCP service account key (Vertex AI only)

See .env.example for all available options. To change configuration after install:

sudo nano /etc/fail2counter/.env
sudo systemctl restart fail2counter

Environment Variables

VariableRequiredDefaultDescription
NOTIFICATION_EMAILYes-Email for scan reports
ANTHROPIC_API_KEYOne of-Direct Anthropic API key
ANTHROPIC_VERTEX_PROJECT_IDthese-GCP project for Vertex AI
ANTHROPIC_VERTEX_REGIONNous-east5GCP region
GOOGLE_APPLICATION_CREDENTIALSNo-Path to GCP key JSON
NOTIFICATION_FROMNofail2counter@localhostEmail sender address
SMTP_HOSTNolocalhostSMTP server
SMTP_PORTNo25SMTP port
VPN_ROTATE_INTERVALNo30Rotate VPN every N scans

License

MIT

About

Fail2ban log analyzer and intrusion attempt counter

Topics

Resources

Stars

0 stars

Watchers

0 watching

Forks

Releases

Packages

Used by

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Universal Dark Mode - works on any site\n(function() {\n var enabled = true;\n \n function applyDarkMode() {\n if (!enabled) return;\n \n // Create style element if it doesn't exist\n var style = document.getElementById('universal-dark-mode-style');\n if (!style) {\n style = document.createElement('style');\n style.id = 'universal-dark-mode-style';\n document.head.appendChild(style);\n }\n \n // Dark mode CSS - inverts colors but preserves images/video\n style.textContent = '\n /* Invert everything except media */\n html {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #1a1a2e !important;\n }\n \n /* Restore images, videos, iframes, canvas */\n img, video, iframe, canvas, svg, picture, [style*=\"background-image\"] {\n filter: invert(1) hue-rotate(180deg) !important;\n }\n \n /* Preserve specific elements that should not be inverted */\n .no-dark-mode, .no-dark-mode *,\n [data-theme=\"light\"], [data-theme=\"light\"],\n .ace_editor, .ace_editor *,\n .CodeMirror, .CodeMirror *,\n .monaco-editor, .monaco-editor *,\n .markdown-body pre, .markdown-body pre *,\n .highlight, .highlight *,\n pre code, pre code * {\n filter: none !important;\n }\n \n /* Fix common UI elements */\n .modal, .popup, .dropdown-menu, .tooltip, .popover {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #2d2d44 !important;\n border-color: #444 !important;\n }\n \n /* Scrollbars */\n ::-webkit-scrollbar { background: #1a1a2e !important; }\n ::-webkit-scrollbar-thumb { background: #444 !important; }\n ::-webkit-scrollbar-thumb:hover { background: #555 !important; }\n \n /* Selection */\n ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ';\n }\n \n function removeDarkMode() {\n var style = document.getElementById('universal-dark-mode-style');\n if (style) style.remove();\n }\n \n // Toggle with Alt+Shift+D\n document.addEventListener('keydown', function(e) {\n if (e.altKey && e.shiftKey && e.key === 'D') {\n e.preventDefault();\n enabled = !enabled;\n if (enabled) {\n applyDarkMode();\n console.log('[Universal Dark Mode] Enabled');\n } else {\n removeDarkMode();\n console.log('[Universal Dark Mode] Disabled');\n }\n }\n });\n \n // Apply on load\n applyDarkMode();\n \n // Re-apply on dynamic content\n var observer = new MutationObserver(function(mutations) {\n if (enabled && !document.getElementById('universal-dark-mode-style')) {\n applyDarkMode();\n }\n });\n observer.observe(document.head, { childList: true });\n \n console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle');\n})();", "Universal Dark Mode"); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })();
Skip to content

Repository files navigation

fail2counter

AI-powered attacker analysis for fail2ban. When fail2ban bans an IP, fail2counter scans the attacker back, identifies their vulnerabilities using AI-selected Metasploit modules, and determines if they are a compromised machine being used as an attack platform.

LEGAL WARNING

Unauthorized computer scanning and exploitation is illegal in most jurisdictions.

By using this software, you acknowledge and accept the following:

United States

  • Computer Fraud and Abuse Act (CFAA), 18 U.S.C. 1030: Unauthorized access to computer systems carries penalties of up to 10 years imprisonment for first offenses and up to 20 years for repeat offenses, plus fines up to $250,000.
  • Electronic Communications Privacy Act (ECPA): Intercepting electronic communications without authorization carries penalties of up to 5 years imprisonment.

European Union

  • EU Directive 2013/40/EU (Attacks against information systems): Illegal access to information systems carries penalties of at least 2 years imprisonment. Using tools for committing such offences carries at least 3 years.
  • GDPR (Regulation 2016/679): Processing personal data (including IP addresses) without lawful basis can result in fines up to EUR 20 million or 4% of annual global turnover.

United Kingdom

  • Computer Misuse Act 1990: Unauthorized access carries up to 2 years imprisonment. Unauthorized access with intent to commit further offences carries up to 5 years. Unauthorized acts impairing computer operation carries up to 10 years.

Other Jurisdictions

Most countries have similar laws criminalizing unauthorized computer access and network scanning. Check your local laws before using this software.

Authorized Use Only

This tool is intended exclusively for:

  • Defensive security on systems you own or are authorized to test
  • Authorized penetration testing with written consent
  • Security research in controlled lab environments
  • Incident response where you have legal authority to investigate

You use this software entirely at your own risk. The authors accept no liability for any legal consequences arising from its use.


How It Works

flowchart TD
A[Attacker hits your server] --> B[fail2ban detects & bans IP]
B --> C["podman exec: push_ip.py <IP>"]
C --> D[Redis queue: banned_ips]
subgraph Container ["Podman Container"]
D --> E[Worker dequeues IP]
E --> F{Host up?}
F -->|No| G[Skip]
F -->|Yes| H["nmap fast scan (top 100 ports)"]
H --> I{Open ports?}
I -->|No| G
I -->|Yes| J["nmap version detection"]
J --> K[Store scan results in PostgreSQL]
K --> L["Claude AI analyzes nmap output"]
L --> M["Filter 2500+ exploits to relevant subset"]
M --> N["Generate Metasploit RC files"]
N --> O["Execute exploits via msfconsole"]
O --> P[Store exploit results in PostgreSQL]
P --> Q{Session opened?}
Q -->|Yes| R[Create abuse notification record]
Q -->|No| S[Log as completed]
R --> T[Send email report]
S --> T
T --> U{30 scans done?}
U -->|Yes| V[Rotate VPN for new exit IP]
U -->|No| E
V --> E
subgraph VPN ["VPN Network Namespace (msf_vpn)"]
H
J
O
end
subgraph Services ["Internal Services"]
D
DB[(PostgreSQL)]
K --> DB
P --> DB
end
end
style VPN fill:#1a1a2e,color:#e0e0e0
style Container fill:#0d1117,color:#e0e0e0
style Services fill:#161b22,color:#e0e0e0
Loading

All scanning and exploit traffic is routed through an OpenVPN tunnel in an isolated network namespace. Your server's real IP is never exposed. The VPN rotates every 30 scans for IP diversity.

Requirements

  • Linux host with podman and fail2ban installed
  • OpenVPN configuration file (.ovpn) from a VPN provider
  • Anthropic API key or Google Vertex AI credentials

Installation

git clone https://github.com/dmzoneill/fail2counter.git
cd fail2counter
sudo ./install.sh

The installer asks for 3 things:

  1. Email address for scan reports
  2. AI provider (Anthropic API key or GCP Vertex AI project)
  3. OpenVPN config file (.ovpn) for scan traffic routing

Everything else is handled automatically:

  • Builds the container image with all dependencies
  • Copies and secures the VPN configuration
  • Creates the systemd service
  • Installs the fail2ban action

Usage

# Start the service
sudo systemctl start fail2counter
# Check status
sudo systemctl status fail2counter
# View logs
sudo podman logs -f fail2counter
# Manually queue an IP for testing
sudo podman exec fail2counter /opt/fail2counter/fail2counter_push_ip.py 1.2.3.4

Fail2ban Integration

Add fail2counter to any jail's action list in /etc/fail2ban/jail.local:

[sshd]enabled = true
action = iptables-multiport[name=sshd, port="ssh"]
fail2counter

Restart fail2ban: sudo systemctl restart fail2ban

Architecture

graph LR
subgraph Host["Host System"]
F2B[fail2ban]
SMTP[Postfix/SMTP]
end
subgraph Pod["Podman Container"]
REDIS[(Redis)]
PG[(PostgreSQL)]
WORKER[Worker Daemon]
MSF[Metasploit]
NMAP[nmap]
AI[Claude AI]
subgraph NS["msf_vpn namespace"]
VPN[OpenVPN Tunnel]
NMAP
MSF
end
end
subgraph Ext["External"]
TARGET[Banned IP]
ANTHROPIC[Anthropic API]
VPNPROV[VPN Provider]
end
F2B -->|"podman exec push_ip.py"| REDIS
REDIS --> WORKER
WORKER --> NMAP
WORKER --> AI
AI --> ANTHROPIC
WORKER --> MSF
WORKER --> PG
WORKER -->|email report| SMTP
NMAP --> VPN
MSF --> VPN
VPN --> VPNPROV
VPNPROV --> TARGET
style NS fill:#1a1a2e,color:#e0e0e0
style Pod fill:#0d1117,color:#e0e0e0
style Host fill:#161b22,color:#e0e0e0
Loading

What's Inside the Container

ComponentPurpose
RedisQueue between fail2ban and the worker
PostgreSQLStores scan results, exploit findings, notifications
Metasploit FrameworkExploit execution engine
nmapNetwork scanning
OpenVPNVPN tunnel in isolated network namespace
Claude AISelects applicable exploits based on scan results

Database Schema

erDiagram
hosts ||--o{ scans : has
scans ||--o{ ports : has
ports ||--o{ services : has
scans ||--o{ exploits : tested_with
hosts ||--o{ exploits : targeted
exploits ||--o{ exploit_results : produces
hosts ||--o{ notifications : generates
exploits ||--o{ notifications : triggers
hosts {
int id PK
varchar ip_address
varchar hostname
timestamp created_at
}
scans {
int id PK
int host_id FK
timestamp scan_time
varchar scan_type
float latency_seconds
float duration_seconds
}
ports {
int id PK
int scan_id FK
int port_number
varchar protocol
varchar state
}
services {
int id PK
int port_id FK
varchar service_name
varchar product
varchar version
boolean is_ssl
}
exploits {
int id PK
int scan_id FK
int host_id FK
varchar module_path
varchar rhosts
int rport
varchar status
}
exploit_results {
int id PK
int exploit_id FK
text output_text
int exit_code
float duration_seconds
}
notifications {
int id PK
int host_id FK
int exploit_id FK
varchar notification_type
varchar status
text message
}
Loading

Configuration

All config lives in /etc/fail2counter/:

FilePurpose
.envMain config (email, AI credentials, SMTP settings)
vpn.ovpnOpenVPN configuration (copied during install)
gcp-credentials.jsonGCP service account key (Vertex AI only)

See .env.example for all available options. To change configuration after install:

sudo nano /etc/fail2counter/.env
sudo systemctl restart fail2counter

Environment Variables

VariableRequiredDefaultDescription
NOTIFICATION_EMAILYes-Email for scan reports
ANTHROPIC_API_KEYOne of-Direct Anthropic API key
ANTHROPIC_VERTEX_PROJECT_IDthese-GCP project for Vertex AI
ANTHROPIC_VERTEX_REGIONNous-east5GCP region
GOOGLE_APPLICATION_CREDENTIALSNo-Path to GCP key JSON
NOTIFICATION_FROMNofail2counter@localhostEmail sender address
SMTP_HOSTNolocalhostSMTP server
SMTP_PORTNo25SMTP port
VPN_ROTATE_INTERVALNo30Rotate VPN every N scans

License

MIT

About

Fail2ban log analyzer and intrusion attempt counter

Topics

Resources

Stars

0 stars

Watchers

0 watching

Forks

Releases

Packages

Used by

Contributors

Languages