SecLayer Documentation
SecLayer provides advanced firewall and intrusion detection for Linux servers. Automate threat detection and response without manual intervention.
Real-time brute force detection across 20+ services with automatic IP blocking.
Self-configuring firewall with auto port discovery and per-IP connection tracking.
Multi-layer Layer 3-4 protection with per-IP connection rate limiting.
What is SecLayer?
SecLayer is a server security suite that provides firewall management, intrusion detection, and automated threat response. It monitors authentication logs, detects attacks in real time, and dynamically updates firewall rules to block malicious traffic — all without manual intervention. Actively maintained and ready for production.
Key Features
Login Failure Daemon
Monitors SSH, FTP, SMTP, cPanel, and 20+ services. Automatically blocks IPs after configurable failure thresholds.
💡Dynamic Firewall
Auto-discovers listening ports and builds precise iptables rules. Zero manual configuration required.
⚡DDoS Mitigation
SYN/ACK floods, ICMP attacks, and application-layer flood protection with graduated rate limiting.
🔒Alerting
Configurable email alerts with per-event type settings and frequency throttling to prevent notification fatigue.
🔎Intrusion Detection
Port scans, exploit attempts, and suspicious process detection with regex-based pattern matching.
🔒Server Security
File integrity monitoring, password policy enforcement, and system-wide security hardening.
Quick Start
- Ensure your server meets the system requirements
- Run the universal installer on your server
- The installer automatically configures firewall rules and the LFD daemon
- Use
seclayercommands to manage rules and monitor threats - Configure alert preferences and thresholds in
/etc/seclayer/