Port Scan Detector

Check fail2ban logs, journalctl for auth failures, ss for connection patterns. Detect scanning (many ports from one IP, rapid failed logins). Generate threat brief.

Install

openclaw skills install @kingaiwork/port-scan-detector