This release adds 2 notable features for engineering teams evaluating rollout.
✓ No known CVEs patched in this version
Topics
+2 more
Summary
AI summaryNew systemd install command adds configurable audit interval and sends Discord summaries.
Full changelog
What's New
Detailed Audit Output
- Ports now show process names (e.g.
443 (caddy), 2244 (sshd)) - Fail2ban shows jail names (e.g.
2 jails: sshd, caddy-auth) - PostgreSQL/MySQL show database names
- SSL certificates show domain names
- SUID binaries listed with full paths
- Failed services listed by name
Discord Audit Summary
chihuaudit auditnow sends a summary to Discord when webhook is configured- JSON output no longer polluted by Discord messages
Install Command
- New
chihuaudit install [--interval=5m]creates and enables a systemd service - Copies binary to
/usr/local/bin/chihuaudit - Service survives reboots
Bug Fixes
- SSL domain collection now correctly resolves nested Caddy certificate directories
- Deduplicated SSL domains across multiple ACME providers
- Filtered internal certificates (e.g.
local) from domain list
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
About girste/mcp-cybersec-watchdog
Comprehensive Linux server security audit with 89 CIS Benchmark controls, NIST 800-53, and PCI-DSS compliance checks. Real-time monitoring with anomaly detection across 23 analyzers: firewall, SSH, fail2ban, Docker, CVE, rootkit, SSL/TLS, filesystem, network, and more.
Related context
Beta — feedback welcome: [email protected]