WarnHack SIEM
Enterprise-grade Linux SIEM for Indian startups & SMEs
One agent. Full visibility. Automated response. Install in 30 seconds, monitor everything — IDS, IPS, FIM, rootkit scanning, centralized logs, and real-time dashboards.
Problems We Solve
Enterprise-level security shouldn't require enterprise-level budgets or teams.
✅ Starts at ₹999/month for 5 servers
✅ Automated IDS + IPS handles detection & response 24/7
✅ Centralized log ingestion, search & correlation
✅ Scheduled rootkit scans with chkrootkit + rkhunter
✅ Real-time FIM with SHA-256 hashing
✅ Cross-server correlation engine detects campaigns
Everything You Need in One Agent
A single lightweight Go binary that monitors everything on your Linux servers.
SSH Brute Force
5+ failures per IP in 60s
SSH Root Login
Any successful root SSH session
New User Created
useradd/adduser events
Sudo Abuse
20+ sudo commands in 5 min
Port Scan
20+ ports probed in 10s
New Listening Port
New LISTEN state detected
Cron Modification
Changes to /etc/cron*
SUID Binary
chmod 4xxx on new files
Reverse Shell
bash >/dev/tcp patterns
Web Scanner
40+ 4xx responses in 60s
Passwd Modified
/etc/passwd hash change
SSH Config Changed
sshd_config modification
12 Purpose-Built Dashboard Views
A modern glassmorphism UI built on Next.js 15 with live updates via WebSocket. All pages update in real-time — no manual refresh.
Security summary, active IPS blocks, FIM changes, rootkit status
Server list with status indicators, risk scores, tags
Active blocks with countdown timers, history, manual block
File change timeline, hash diffs, critical file highlighting
Server status grid, scan history, detailed findings
Filter, acknowledge, resolve — with severity badges
KQL search bar, saved searches, CSV export
Event volume charts, top attackers, MTTD/MTTR metrics
Cross-server attack visualization & attack graph
SOC2/ISO 27001 scores, control status, report export
World map with severity-colored attack bubbles
Drag-and-drop widget builder — create your views
Beyond Basic Monitoring
Dynamic risk score 0-100 per server, updated every 60 seconds. Factors in alerts, IPS blocks, rootkit status, and FIM changes.
Detects coordinated attacks targeting multiple servers. 5-minute correlation window with visual attack graph.
Automatic IP reputation via AbuseIPDB. Known attackers (score ≥50) auto-escalate to critical severity.
MaxMind GeoLite2 integration. Every event enriched with country, city, coordinates. Powers the threat map.
Z-score anomaly detection on event patterns. Learns normal baselines per server, flags statistical outliers.
Drag-and-drop widget placement. Mix metrics, alerts, logs. Save, share, and use on mobile.
Multi-Channel Alerts
Get alerted wherever your team works. Severity filtering per channel, test notifications, and graceful degradation.
SMTP-based with severity-colored templates
Slack
Webhook integration with color-coded attachments
Telegram
Bot API with emoji severity indicators
Webhook
Custom HTTP POST to any endpoint
PagerDuty
Events API v2 for on-call escalation
Enterprise-Grade Security
- JWT with access (15min) + refresh (7-day) token rotation
- bcryptjs with 12-round hashing
- TOTP MFA — Google Authenticator, Authy
- Agent Auth: x-agent-token + JWT + mTLS
- 4 roles per tenant: Owner, Admin, Member, Viewer
- Rate Limiting: Auth 15/15min · Agent 30/10s · API 100/min
- Helmet.js — CSP, X-Frame-Options, HSTS
- Strict CORS origin whitelist
- Joi schema validation on every endpoint
- Generic error messages — no info leakage
- TLS 1.2+ enforced on all connections
- MongoDB Atlas encryption at rest
- mTLS with client certificates + CA verification
- API keys SHA-256 hashed
- MFA secrets excluded from all API responses
One Command. That's It.
Auto-detects architecture, installs as systemd service, generates config, and starts monitoring immediately.
$ curl -sSL https://install.warnhack.io | bash
✓ Architecture detected: amd64
✓ Agent installed to /usr/local/bin/
✓ Systemd service created
✓ Config at /etc/warnhack/agent.yaml
🔒 WarnHack agent is now monitoring this server.
Built With Modern Technology
Go 1.24 static binary (zero dependencies)
Node.js 20, Express 4, MongoDB Atlas, Redis
Next.js 15, TypeScript, Tailwind CSS, Framer Motion
ClickHouse (columnar storage, materialized views)
JWT + TOTP MFA + mTLS + bcryptjs
Socket.io (WebSocket with fallback)
Simple, Transparent Pricing
All plans include: real-time dashboard, log search, auto-updates, multi-tenant team management.
Secure Your Servers Today
Install the WarnHack agent in 30 seconds and get full visibility into your Linux infrastructure. Start free — no credit card required.