Agippy

    Geo-IP firewall automation for Linux servers.

    Analyse auth logs, map failed-login IPs to countries, and generate iptables or ipset firewall scripts. Free for the core flow. Paid adds Wireshark IDS, MCP, and an embedded LLM.

    Free: blacklists + ipset. Paid: + wireshark IDS, MCP server, embedded LLM, fresh IP2Location DB.

    root@edge-01: ~
    _

    How it works

    Three commands. Auth-log noise becomes a firewall script.

    $ agippy analyse

    Scan auth logs

    Sift /var/log/auth.log for failed-login patterns. Count attempts per IP. Export to CSV or Excel if you want a paper trail.

    $ agippy create ipblacklist

    Map IPs to countries

    Geolocate via IP2Location. Build per-IP and per-country blacklists. Whitelist what should never be blocked.

    $ agippy create ipset

    Generate ipset script

    Emit a shell script that loads the rules into ipset — orders-of-magnitude faster than per-IP iptables for large lists.

    Editions

    Start free. Upgrade when you need the rest.

    Free

    Everything you need for the core firewall workflow.

    • analyse, ipset, blacklist, countrylist
    • Bundled IP2Location LITE database
    • doctor, init, status, examples
    • Same /usr/bin/agippy as paid — swap editions any time
    Loading…
    Paid

    Paid

    Everything in Free, plus the full feature set.

    • Wireshark integration: read pcap, capture, conversations, follow streams
    • Seven concurrent IDS checks: port scan, beaconing, DNS tunneling, cleartext creds, suspicious ports, ARP spoofing, ICMP tunneling
    • MCP server exposing 18 tools to Claude Code and other MCP clients
    • Embedded LLM for in-CLI explain and ask
    • Fresh IP2Location commercial database refresh
    Buy on PrivateStudio shop→ shop

    Both editions install to the same paths. apt installs from /opt/agippy/, symlinked as /usr/bin/agippy. Conflicts/Replaces lets you switch editions with dpkg -i in either direction.

    Paid — beyond the firewall

    Packet analysis, IDS, and MCP — same binary.

    Wireshark inside

    Read pcap files, capture live traffic, follow TCP streams, run protocol-hierarchy reports. Backed by tshark or gopacket. The detect subcommand runs seven IDS checks in parallel.

    $ agippy wireshark detect capture.pcap

    MCP server

    agippy mcp serve exposes geo-IP and Wireshark tooling to Claude Code and other MCP clients over stdio. Bring auth-log triage and pcap analysis into your agent loop.

    $ claude mcp add agippy agippy mcp serve