xvark
A headless security monitor for whatever host and network it runs on.
LAN presence
Passive ARP listening plus active arp-scan sweeps build a device inventory with join and leave events. Trusted devices, labels, and presence history.
Host egress
A live per-process connection table, scheduled and on-demand capture digests (top destinations, 5-tuple flows, DNS queries, TLS SNI and JA3, cleartext HTTP Host), retained pcaps, a continuous ring buffer, and alerts the first time this host contacts a new external destination.
Findings and intel
A deterministic rule engine flags cleartext credentials, rare ports, DNS tunnelling and DGA patterns, Tor/SOCKS, exfil volume and more. Offline GeoIP (ASN, country) and public blocklists (abuse.ch Feodo Tracker, SSLBL, Spamhaus DROP, URLhaus) are matched locally. No LLM required.
Alerts
One Apprise pipeline: Discord, SMS, desktop, ntfy, email and 80+ more channels, with dedup, SMS rate limits and quiet hours.
Status: version 0.4, in development on Linux, not yet publicly released. Built to plug into Guaardvark.