NetHawk is a state-of-the-art AI-IPS (Intrusion Prevention System) designed for real-time network traffic analysis, threat scoring, and automated defense. Built with a dual-engine architecture, it combines deep packet inspection (DPI) with an AnomalyGuard self-learning model to detect both known vulnerabilities and zero-day threats.
- 🛡️ Multi-Vector Threat Analysis: Real-time detection of DoS, DDoS, Port Scans, SQL Injections, Botnets, and more across 24+ attack categories.
- 🧠 AnomalyGuard (Zero-Day Detector): A specialized neural network that learns your network's normal behavior and flags unknown anomalies that traditional signatures might miss.
- 🤖 AI Security Advisor: Integrated with TinyLlama-1.1B, providing human-readable incident analysis and mitigation strategies directly on your dashboard.
- 🌐 Dual-Stack Support: Full support for both IPv4 and IPv6 traffic analysis.
- 💻 Dynamic Web Dashboard: A premium, glassmorphism-style web interface (React-inspired) for remote monitoring and deep threat investigation.
- 📊 Terminal TUI: A beautiful, real-time Terminal User Interface powered by
Rich, perfect for headless server monitoring. - ⚡ Hardware Acceleration: Automatically detects and utilizes NVIDIA CUDA for ultra-fast AI inference.
- 🔑 Persistent Configuration: Seamlessly manages API tokens (HuggingFace) and system settings via
config.ini.
- Windows 10/11 or Linux
- Npcap (Windows) or Libpcap (Linux)
- Python 3.10+
- (Optional) NVIDIA GPU with CUDA for better performance
-
Clone the repository:
git clone https://github.com/ThemeHackers/NetHawk.git cd NetHawk -
Install dependencies:
pip install -r requirements.txt
-
Initialize Configuration: Create or edit
config.iniin the root directory:[Notifications] BOT_TOKEN = YOUR_DISCORD_BOT_TOKEN CHANNEL_ID = YOUR_DISCORD_CHANNEL_ID ALERT_COOLDOWN = 60 [Model] WEIGHT_PATH = model.onnx MODEL_PATH = model.onnx.prototxt HF_TOKEN = YOUR_HUGGINGFACE_TOKEN (Optional) [Performance] BATCH_SIZE = 32 THROTTLE_DELAY = 0.05
Run the main script with Administrator/Root privileges:
# Auto-detect best interface and start sniffing
python nethawk.py
# Specify interface and BPF filter
python nethawk.py --iface "Ethernet" --filter "tcp port 80" --verboseOnce started, the system will launch two interfaces:
- Terminal UI: Real-time stats and packet monitor in your console.
- Web Dashboard: Open
http://127.0.0.1:8000in your browser for the full visual experience.
NetHawk classifies traffic into the following 24 categories:
- Normal (Clean Traffic)
- DoS / DDoS (Hulk, GoldenEye, Slowloris, etc.)
- Web Attacks (SQL Injection, XSS, Brute Force)
- Network Scans (Port Scan, Reconnaissance)
- Malware Activity (Botnets, Backdoors, Worms, Shellcode)
- Exploits & Fuzzers
NetHawk is designed for security professionals and network administrators. Always ensure you have explicit permission to monitor network traffic on your chosen environment.
Contributions are welcome! Whether it's improving the AI models, adding new protocol support, or enhancing the dashboard UI, feel free to submit a Pull Request.
Author: ThemeHackers
License: MIT License