Demo
A small Linux VM runs sshd and nginx on the open internet — no valid
credentials, no dynamic content, just attack bait. fail2zig tails their logs and installs real
kernel-level nftables
DROP rules against real attackers. Everything below is live — no synthesised events, no dashboards
dressed up as daemons, no demo button.
demo.fail2zig.com/events fail2zig/banned_v4 · 1 Hz poll loading banned set… demo.fail2zig.com/metrics · 1 Hz poll lines parsed
—
0 lines/sec (EMA)
lines matched
—
attack-pattern hits
bans (total)
—
lifetime
active bans
—
currently in nft set
resident memory
—
RSS
uptime
—
since daemon start