Guardian Ops
Enables network vulnerability scanning and CVE detection through an AI assistant, with optional remote port blocking via Discord bot.
README
Guardian Ops
A comprehensive network security platform that integrates automated vulnerability scanning, CVE detection, and remote firewall management. Built for seamless user interaction via AI assistants (Puch AI), with a web dashboard for audit logs and a Discord bot for instant port blocking.
Guardian Ops empowers users to scan their networks, detect threats, and respond in real-time—without leaving their chat interface.
What It Does
Guardian Ops provides end-to-end security operations through a conversational AI interface:
Core Workflow
- User Interaction: Connect via Puch AI (e.g., WhatsApp) and provide your IP/hostname. Choose a scan type (quick/full/port check/vuln/network discovery).
- Scanning & Detection: The MCP server performs Nmap-based scans, detects open ports/services, and chains CVE searches across CIRCL, NVD, and Vulners APIs.
- Reporting: Instant reports with open ports, services, and potential vulns. If vulnerabilities are found, alerts the user.
- Dashboard Access: View scan history and details via a secure web dashboard.
- Remediation: For detected vulns on open ports, get a direct link to authorize and use the Discord bot to block risky ports remotely.
Key Features
- Conversational Scanning: Natural language commands like "OG quick scan on my-ip.com" via Puch AI.
- Multi-API CVE Chaining: Aggregates vulns from CIRCL (free), NVD (key optional), and Vulners (key optional) with deduplication.
- Audit Logging: Per-user SQLite database tracks all scans with timestamps and results.
- Web Dashboard: Dark-themed UI for viewing/deleting logs and scan details.
- Remote Port Management: Discord bot blocks/unblocks TCP ports using iptables (persistent via netfilter-persistent).
- Security-First: Bearer auth for MCP, env-based secrets, input validation, and single-user Discord authorization.
- Background Processing: CVE checks run asynchronously to keep scans fast.
Security & Compliance
- Scans log to a dashboard for audit trails.
- Port blocking uses UFW-compatible iptables chains.
- No sensitive data exposed in responses.
- Rate-limited concurrent requests to avoid API abuse.
Technical Architecture
Components
- MCP Server (
mcp_server.py): FastMCP-based server for Puch AI integration. Handles scans with Nmap, CVE queries via httpx, and logging to SQLite. - Dashboard (
dashboard.py): FastAPI app with Jinja2 templates for user-facing logs and details. - Discord Bot (
bot.py): discord.py bot for port management, executing shell scripts. - Shell Scripts (
scripts/):block_port.shandunblock_port.shfor iptables rules. - System Service (
services/capstonebot.service): Systemd for bot auto-start. - Database: SQLite (
guardian_scans.db) for scan logs.
Data Flow
User (Puch AI) → MCP Server (Scan Request) → Nmap Scan + CVE APIs → Report + Vuln Alert
↓
Dashboard (Logs) ← SQLite ← Scan Results
↓ (If Vulns)
User → Discord Bot (Authorize) → Shell Scripts → iptables → Persistent Rules
Tech Stack
- Backend: Python 3.8+, FastMCP, FastAPI, discord.py, Nmap, httpx.
- Database: SQLAlchemy + SQLite.
- APIs: CIRCL CVE, NVD, Vulners.
- Frontend: Jinja2, HTML/CSS (dark theme, Poppins font).
- OS: Ubuntu 20.04+ (iptables, netfilter-persistent).
Prerequisites
- Ubuntu Server 20.04+.
- Python 3.8+.
- Nmap installed (
sudo apt install nmap). - netfilter-persistent for rule persistence (
sudo apt install iptables-persistent). - Discord Bot Token (create at Discord Developer Portal).
- Optional: NVD/Vulners API keys for enhanced CVE searches.
- sudo privileges for iptables.
Installation
1. Clone the Repository
git clone <your-repo-url>
cd guardian-ops
2. Environment Setup
Create .env in the root:
# MCP Server
AUTH_TOKEN=your_mcp_auth_token_here
MY_NUMBER=your_phone_number_here # e.g., 919876543210
VULNERS_API_KEY=your_vulners_key_optional
NVD_API_KEY=your_nvd_key_optional
DASHBOARD_URL=http://your-server-ip:8000 # Update with your dashboard URL
# Discord Bot
DISCORD_TOKEN=your_discord_bot_token_here
AUTHORIZED_USER_ID=your_discord_user_id_here # Numeric user ID
Load env: source .env (or use python-dotenv).
3. Install Dependencies
# MCP Server & Dashboard
pip install -r requirements-mcp.txt # Includes fastmcp, nmap, httpx, sqlalchemy, fastapi, etc.
# Discord Bot
cd discord-bot
python3 -m venv venv
source venv/bin/activate
pip install -r requirements.txt # discord.py, python-dotenv
4. Database Setup
The SQLite DB auto-creates on first scan. Run migrations if needed:
python -c "from mcp_server import engine, Base; Base.metadata.create_all(engine)"
5. Discord Bot Scripts
cd discord-bot/scripts
chmod +x block_port.sh unblock_port.sh
6. System Services
For Discord Bot:
sudo cp discord-bot/services/capstonebot.service /etc/systemd/system/
sudo systemctl daemon-reload
sudo systemctl enable capstonebot.service
sudo systemctl start capstonebot.service
For MCP Server & Dashboard: Run manually or via systemd (see below).
7. Start Services
- MCP Server:
python mcp_server.py(runs on :8086). - Dashboard:
python dashboard.py(runs on :8000). - Test:
sudo journalctl -u capstonebot.service -ffor bot logs.
Usage
User Workflow (Via Puch AI/WhatsApp)
- Message "hi" to Guardian Ops (OG) for the menu.
- e.g., "OG quick scan on 192.168.1.100" → Gets scan report.
- If vulns found: Report includes "Go to Discord bot: https://discord.com/oauth2/authorize?client_id=1436272504128929852" to authorize and block ports.
- View history: Use dashboard link in reports (e.g., http://your-server:8000).
Scan Commands
| Command | Example | Description |
|---|---|---|
| Quick Scan | OG quick scan on scanme.nmap.org |
Fast common ports + basic vulns. |
| Full Scan | OG full scan on example.com |
Thorough OS/service/vuln scan. |
| Port Check | OG port check on example.com port 80 |
Specific port status + service. |
| Vuln Scan | OG vuln scan apache 2.4 |
CVE search for service/version. |
| Network Discovery | OG network discovery 192.168.1.0/24 |
Find active hosts in subnet. |
Discord Bot Commands (Post-Scan Remediation)
Invite bot: https://discord.com/oauth2/authorize?client_id=1436272504128929852
(Authorize only once; commands restricted to your user ID.)
| Command | Usage | Description |
|---|---|---|
!ping |
!ping |
Bot responsiveness. |
!blockport |
!blockport 8080 |
Block TCP port (persistent). |
!unblockport |
!unblockport 8080 |
Unblock port. |
!helpme |
!helpme |
Command list. |
Example:
User: !blockport 8080
Bot: Blocked TCP port 8080.
Dashboard
- Access: http://your-server:8000
- Login: Enter Puch User ID.
- Features: View/delete logs, scan details.
Security Considerations
- Auth: MCP uses bearer tokens; Discord limits to one user ID.
- Validation: IP/port/service inputs sanitized; scans limited (e.g., max 256 hosts).
- Persistence: iptables rules saved via netfilter-persistent.
- APIs: Fallback to free CIRCL if keys invalid.
- Logs: No sensitive data stored; user-owned DB.
Warning: Scans may trigger IDS/IPS. Use responsibly on authorized networks. Port blocking requires sudo—test in safe env.
Project Structure
guardian-ops/
├── nmap_puch_mcp.py # Puch AI MCP server
├── dashboard.py # FastAPI dashboard
├── requirements.txt # MCP + dashboard deps
├── templates/ # HTML: login.html, dashboard.html, scan_detail.html
├── discord-bot/
│ ├── bot.py # Discord bot
│ ├── requirements.txt # Bot deps
│ ├── .env # Bot env (or root)
│ ├── scripts/
│ │ ├── block_port.sh
│ │ └── unblock_port.sh
│ └── services/
│ └── capstonebot.service
└── guardian_scans.db # Auto-generated SQLite
Troubleshooting
- MCP Won't Start: Check AUTH_TOKEN/MY_NUMBER; verify Nmap (
nmap --version). - Scans Timeout: Increase timeouts or use faster targets (e.g., scanme.nmap.org).
- Bot Unauthorized: Confirm AUTHORIZED_USER_ID (numeric, via Discord dev tools).
- Dashboard No Logs: Ensure Puch User ID matches; check SQLite.
- Vulns Not Found: Add API keys; CIRCL is default fallback.
- Logs:
journalctl -u capstonebot(bot); console for MCP/dashboard.
Customization
- Add Scans: Extend
@mcp.toolinmcp_server.py; updateguardian_opsparser. - UDP Support: Modify shell scripts:
iptables -I ufw-before-input -p udp --dport $PORT -j DROP. - Dashboard: Add auth (e.g., JWT) or export logs.
- Alerts: Integrate email/SMS for high-CVSS vulns.
License
Educational capstone project—MIT License. Use responsibly.
Support
- Issues: Check troubleshooting; verify prereqs/permissions.
- Community: Discord bot for testing; Puch AI for scans.
- Enhancements: PRs welcome!
Note: Guardian Ops handles powerful security tools. Always comply with laws and obtain permission for scans. Test on isolated networks first.
推荐服务器
Baidu Map
百度地图核心API现已全面兼容MCP协议,是国内首家兼容MCP协议的地图服务商。
Playwright MCP Server
一个模型上下文协议服务器,它使大型语言模型能够通过结构化的可访问性快照与网页进行交互,而无需视觉模型或屏幕截图。
Magic Component Platform (MCP)
一个由人工智能驱动的工具,可以从自然语言描述生成现代化的用户界面组件,并与流行的集成开发环境(IDE)集成,从而简化用户界面开发流程。
Audiense Insights MCP Server
通过模型上下文协议启用与 Audiense Insights 账户的交互,从而促进营销洞察和受众数据的提取和分析,包括人口统计信息、行为和影响者互动。
VeyraX
一个单一的 MCP 工具,连接你所有喜爱的工具:Gmail、日历以及其他 40 多个工具。
graphlit-mcp-server
模型上下文协议 (MCP) 服务器实现了 MCP 客户端与 Graphlit 服务之间的集成。 除了网络爬取之外,还可以将任何内容(从 Slack 到 Gmail 再到播客订阅源)导入到 Graphlit 项目中,然后从 MCP 客户端检索相关内容。
Kagi MCP Server
一个 MCP 服务器,集成了 Kagi 搜索功能和 Claude AI,使 Claude 能够在回答需要最新信息的问题时执行实时网络搜索。
e2b-mcp-server
使用 MCP 通过 e2b 运行代码。
Neon MCP Server
用于与 Neon 管理 API 和数据库交互的 MCP 服务器
Exa MCP Server
模型上下文协议(MCP)服务器允许像 Claude 这样的 AI 助手使用 Exa AI 搜索 API 进行网络搜索。这种设置允许 AI 模型以安全和受控的方式获取实时的网络信息。