Skip to content

feat: add ssh-login-monitor module to store - #1

Merged
ralyodio merged 1 commit into
profullstack:masterfrom
pxivory-max:feat/ssh-login-monitor-module
May 21, 2026
Merged

ralyodio merged 1 commit into
profullstack:masterfrom
pxivory-max:feat/ssh-login-monitor-module

Conversation

@pxivory-max

Copy link
Copy Markdown
Contributor

Summary

  • Adds a new free/MIT-licensed SSH Login Monitor module to boilerplates/
  • Monitors /var/log/auth.log for SSH login events, detects brute-force patterns, and emits ThreatEvents
  • Follows the same structure as existing boilerplates (mod.toml, src/index.ts, package.json, etc.)

Module Details

Field Value
Name ssh-login-monitor
Category Security / Monitoring
License MIT
Pricing Free
OS Support Linux

What it does

  1. Tails auth log file for SSH events (configurable path)
  2. Parses failed password attempts and successful logins
  3. Emits high/critical severity events when brute-force patterns exceed threshold
  4. Emits info events for successful SSH logins (audit trail)
  5. Persists file offset via ctx.setState to avoid re-processing on restart

Related

Test plan

  • Verify module structure matches existing boilerplate conventions
  • Confirm TypeScript compiles with pnpm build
  • Review mod.toml metadata is complete and correct

Adds a new community module that monitors SSH authentication logs for
brute-force patterns and emits ThreatEvents. Follows the same structure
as the existing free-module boilerplate (mod.toml, src/, package.json).

Co-Authored-By: Claude Opus 4 <noreply@anthropic.com>

let content: string;
try {
const buf = await readFile(logPath, { encoding: 'utf8' });
@ralyodio

Copy link
Copy Markdown
Contributor

YOu have a blocking file system race condition. Otherwise looks good to me! I'll merge as soon as the checks pass.

@ralyodio

Copy link
Copy Markdown
Contributor

@ralyodio
ralyodio merged commit 785bf5f into profullstack:master May 21, 2026
7 of 8 checks passed
ralyodio added a commit that referenced this pull request Aug 14, 2026
…133)

Nine of the seventeen repositories asked in today's batch had under
fifteen stars and five had two or fewer. In several the request arrived
as issue #1 and pull request #1 of a repository nobody has looked at
yet — coldmill, EntityIdentifierResolver, gomorph, svarm, claude-bridge.

Two reasons to stop, and the second is the one that matters:

  They will not be read. A repository with no stars and no issues has no
  maintainer attention to win. The whole premise of asking first is that
  somebody is there to answer.

  It is the shape of activity the acceptable use policy is least
  forgiving about. Bulk unsolicited pull requests are judged on the
  pattern, not on each one, and "opened issue #1 in forty repositories
  with no stars" is that pattern described exactly.

TCFEED_MIN_STARS, default 5, 0 turns it off. Five rather than fifteen
because the aim is to drop repositories that are unattended, not small
ones — nsproxy at 84 stars and ZeroDroid at 6 are real projects with
real users, and the floor should not have an opinion about them.

Placed above the scan, so a repository under the floor is never cloned.
It costs one metadata call and saves a clone.

Remembered rather than reconsidered, which is the one real trade here: a
star count can change where `archived` cannot, so a repository that
grows past the floor later will not come back. Re-deciding it every run
would instead burn one of the twenty slots each time and crowd out
candidates that would actually be scanned.

Verified both directions against an isolated cache: at 999999 every
repository is gated and nothing is cloned, and the table comes back
empty; at 0 no repository is gated and the table builds as before.

Co-authored-by: Claude Opus 5 <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants