Behavioral crypto mining defense. Catches miners by what they do, not what they look like. One script. Zero dependencies. Free forever.
Built from real attack experience. Every feature exists because something went wrong without it.
Doesn't care what the binary looks like. Detects mining behavior — Stratum protocol, sustained CPU + network combos.
Protocol. Behavior. Signatures. Fingerprinting. Wallet forensics. If a miner runs, it dies.
One Python file. No pip. No Docker. No config. Works on any Linux with Python 3.6+.
--fortify installs multiple independent persistence layers. Kill one — the rest bring it back.
--uninstall removes every trace. Service files, cron, flags, binary. One command. Clean exit.
--status shows protection state at a glance. Active layers, last scan, miners killed.
Every kill extracts the attacker's wallet address. The optional plugin reports it to a crowd-sourced database. The more servers that run it, the faster wallets get burned.
Stratum protocol detection: in our testing, zero false positives. CPU behavioral analysis uses configurable thresholds with --whitelist support.
Scan-only by default. Nothing dies without your explicit permission. You choose --kill. Every action requires your yes.
Zero telemetry. Never phones home unless you tell it to. --uninstall removes everything. Your server, your rules.