Dashboard

Tasks found: 5 — each one comes with a command. Click the copy icon: in the demo we show the result right away.
Suricata — Not running sudo systemctl enable --now suricata
PSAD — Not running sudo systemctl enable --now psad
clamd daemon — Not running sudo systemctl enable --now clamav-daemon
Monit — Not running sudo systemctl enable --now monit
Security updates — 3 patches pending sudo apt update && sudo apt upgrade
System status
UFW Firewall Active
Fail2ban Active
IPset ipsum Active
Load (1/5/15) 2.11 / 1.60 / 1.69
WebAuthn keys 3 keys registered
ClamAV Inactive
AIDE No changes detected
CrowdSec Active
Suricata Not running
SSL Certificates 91 Days left
Monit Inactive
SSH sessions 2 Active sessions 337 Failed today
MySQL Active
Auditd 4 Logins today 5 Failed attempts
ModSecurity 188 Blocked
Falco Active
Logwatch 11.10.2026
Security score
75 of 100
Attention
Security score
UFW Firewall Active
Fail2ban 26 active jails
IPset ipsum 117,844 IPs
2FA WebAuthn 3 keys registered
Lynis Audit 90/100
Root login no
Password login Key only
SSH settings in order
Web server hardening in order
Attacks today 1,981
ClamAV No threats detected
clamd daemon Not running
AIDE No changes detected
debsums All package files intact
CrowdSec 2,031 Active bans
Suricata Not running
Falco Falco is active; no suspicious events detected
Monit Not running
SSL Certificates 91 Days left
External exposure 4 ports exposed
AppArmor (MAC) In enforce mode: 44
PSAD Not running
Disk 64%
Security updates 3 patches pending

What this Linux server security dashboard shows

This is a live, read-only demo of a self-hosted security panel for a single Linux server. Everything on screen is produced on the machine itself: there is no agent to deploy, no cloud collector, and no telemetry leaving the host. The panel is PHP and MySQL on top of the tools you already run, which means you can read every line of it before you trust it with a server.

The sidebar leads to 18 modules grouped the way an incident actually unfolds. Intrusion detection covers Fail2ban, Suricata, CrowdSec, PSAD and Falco. Integrity covers AIDE, debsums and AppArmor. Hygiene covers Lynis audits, pending security updates, SSL expiry, SSH sessions, open ports, disk health and database status. Each one is a page in its own right rather than a widget on a wall of graphs.

Figures and addresses in this demo are synthetic — all IP addresses come from the RFC 5737 documentation ranges, so nothing here points at a real host. On your own server the same pages read your real logs.