# Changelog ## 0.1.0 (2026-09-15) First release. - Real-time detection from SSH, sudo, Windows Security and OpenSSH event logs, Apache/nginx and IIS access logs, decoy ports and custom rules. - Per-attacker campaigns, live dashboard, web push, webhooks, email. - Automatic blocking on Linux (ipset/iptables), macOS (pf) and Windows (Windows Firewall), with escalating durations and a never-block list. - Installers for systemd, launchd and Windows Task Scheduler. - Self-contained executables for Linux, macOS and Windows (x64 and arm64), no Node.js install needed. - Canary account names and URLs: critical alert and immediate block on first use. - Tarpit decoy ports that hold scanners and count the attacker time wasted. - Peer block sharing between your own hosts through a token-protected feed. - Hourly exposure self-check of the host (SSH password auth, root login, firewall, open ports, alert channels) with fixes. - Daily digest on every configured channel. - Settings screen with validation and live apply. - Named users with viewer, operator and admin roles, and an audit trail of every action.