Server Warden
ENRUUK
Autonomous server defense

Server Warden

Not just detect a problem. Observe it, limit the damage, restore trusted state and prove the result.

Linux protectionRecovery ProofProtected vs UnprotectedRead-only audit

1. Two proofs instead of promises

Server Warden should not ask a buyer to trust marketing. Before purchase, a visitor can inspect their own server with a read-only audit and then watch the protection lifecycle in an interactive security lab.

1

Audit your server for free

45 read-only checks with no installation or changes. The script produces a local HTML/TXT report with risks and recommendations.

2

See the protection work

Security Lab runs controlled scenarios and shows protected vs unprotected behavior, timeline, recovery and independent proof.

2. A closed protection loop

OBSERVEstate and telemetry
DETECTunexpected change
CORRELATEcontext and evidence
CONTAINlimit damage
RECOVERrestore known-good
VERIFYprove the result
RECOVERED ≠ VERIFIED. A restart or rollback is not proof. VERIFIED is earned only after independent health, hash, listener, firewall, identity and scenario-specific checks.

3. Free server audit

The audit is the first persuasion loop. It is a one-shot read-only diagnostic, not the Server Warden agent.

Host baseline

OS release · kernel · uptime/load · disk usage · memory/swap

Exposure

Listening TCP sockets · public SSH exposure · Docker TCP API · database/service ports

Firewall

UFW · nftables · iptables

SSH & accounts

Failed-login signals · top source IPs · effective SSH config · UID 0 users · sudo/admin groups · authorized_keys permissions

nginx / web

nginx version · config test · suspicious log patterns and paths · server inventory · risky directives

Filesystem

Sensitive-path markers · world-writable project files · executables in temp directories

Persistence / systemd

SUID snapshot · cron · failed services · suspicious systemd Exec lines

Packages & processes

Update signal · fail2ban · top CPU processes · suspicious process indicators

Docker

Socket permissions · containers · privileged/network risk

Resilience / ops

Recent backups · backup freshness · Let’s Encrypt certificates · disk pressure

Report

Local HTML/TXT report · risk score · recommendations

4. Server Warden modules

Do not publish a crude “13/17 complete” counter. Show the real capability status: available now, infrastructure-dependent, in qualification, or dependent on customer endpoints. The product capability matrix should remain the source of truth.

AVAILABLE NOW

Core Platform

HS-CORE

Signed policy, module supervision, Action Broker, leases, approvals, kill switch, generation fencing.

AVAILABLE NOW

Integrity & Self-Heal

HS-INTEGRITY

File/config drift, one-byte and binary replacement, permission drift, persistence, safe repair and Recovery Proof.

AVAILABLE NOW

Network Defense

HS-NET

Unauthorized listeners, firewall/posture drift, network observation and controlled isolation.

AVAILABLE NOW

Identity Defense

HS-IDENTITY

Unauthorized accounts/admin, identity drift and privileged-state checks.

AVAILABLE NOW

Ransomware Shield

HS-RANSOM

Mass file rewrites, canaries, containment and recovery workflows.

AVAILABLE NOW

Egress / Exfiltration

HS-EGRESS

Unexpected egress and exfiltration signals; observe first, enforcement through network policy.

AVAILABLE NOW

Deception Fabric

HS-DECEPTION

Honeytokens and deception signals that should never appear in legitimate work.

AVAILABLE NOW

Hardening Posture

HS-POSTURE

Search-path and privileged-binary posture checks with evidence-based findings.

AVAILABLE NOW

Forensics / Time Machine

HS-FORENSICS

Timeline, replay, signed proof packs and final-state verification.

AVAILABLE NOW

Compliance Evidence

HS-COMPLIANCE

Evidence-to-control mapping; never presents a certification without evidence.

AVAILABLE NOW

Security Commander

HS-AI

Deterministic triage plus AI advisory; AI never gets an unrestricted privileged shell.

INFRA-DEPENDENT

Guardian Recovery

HS-GUARDIAN

Single-plane out-of-band recovery exists; multi-plane HA needs an independent second plane.

INFRA-DEPENDENT

Digital Twin

HS-TWIN

A/B counterfactual and twin graph are available; full isolated live proof needs dedicated lab infrastructure.

IN QUALIFICATION

Application Shield / Veil

HS-APPLICATION

Survival/bundle foundation exists; full App Shield is being completed.

IN QUALIFICATION

DDoS Reflex

HS-DDOS

Requires a dedicated load-generation and hardware qualification environment before public performance claims.

CUSTOMER ENDPOINT

Enterprise Integrations

HS-INTEGRATIONS

Local JSON/CEF and ingest foundations exist; live remote delivery depends on customer endpoints/credentials.

IN QUALIFICATION

Windows parity

WINDOWS

Linux is the qualified baseline today; Windows parity requires dedicated validation hosts.

5. Architecture

Customer / Internet / infrastructure
Server Warden CommandPolicy · Event · Audit · Action Broker · Evidence
Sentinelhost telemetry · detectors · permitted actions
Guardian Planeout-of-band recovery · rebuild
External / Integrationssite checks · SIEM export · evidence

Effectful actions pass through the Action Broker; detectors and AI do not receive a generic privileged shell. Security Commander assists with triage and explanation while deterministic protection continues without an LLM.

6. Security Lab

The public terminal is a strict allowlisted DSL, not an arbitrary browser shell. The strongest mode is Protected vs Unprotected: the same controlled activity is applied to identical environments.

ATTACKER / TEST
warden-demo> run firewall-drift --compare
00.000 policy changes
00.094 drift observed
MACHINE
Protected: RECOVERING
Unprotected: DRIFT REMAINS
Evidence: collecting
SERVER WARDEN
DETECTED
CORRELATED
RECOVERED
VERIFIED
Recovery Prooftimeline + evidence available

7. Getting started

  1. Optionally run the free audit and keep the report.
  2. Purchase one license per protected server/instance under the current commercial model.
  3. Install and enroll through the current customer-specific delivery flow; never publish permanent secrets in static docs.
  4. Create the baseline and verify heartbeat, policy version and active modules.
  5. Choose which conditions are detect-only, auto-contain, auto-recover or approval-gated.
  6. Operate through incidents, timeline, Recovery Proof and reports.

8. Current status

Available now on Linux: trusted core, integrity/self-heal, network, identity, ransomware, egress, deception, posture, forensics/proof, compliance evidence and Security Commander.

Infrastructure-dependent: multi-plane Guardian HA and evaluator-grade isolated Twin/LiveFire.

In qualification: full App Shield, DDoS Reflex, Windows parity and live remote enterprise connectors.

9. Price

Server Warden · 1 server

999 UAH/ month

Annual: 9,990 UAH. USD should remain an indicative dynamic reference only; settlement is in UAH.

10. Who it fits

Good fit

VPS and dedicated servers, production services and teams that need more than alerts: controlled containment, recovery and evidence.

Not a replacement for

Hardware/firmware security, provider-scale DDoS scrubbing, or capabilities the endpoint has no authority to perform. Those boundaries should be stated explicitly.

Facts first. Demonstration second. Decision last.