Skip to main content

Offenders — Fail2Ban investigation and diagnostics TUI

PyPI Python Release checks License: MIT

Offenders is a terminal-first investigation and diagnostics tool for Fail2Ban. Combine historical ban activity with current jail state, investigate IPs and jails, and explore IP/ASN/Country summaries over SSH or in a local Linux terminal. Use explicit Registration/RDNS lookups, optional GeoIP, manual Coverage and validation, CSV Export, and global contextual ? Help.

Offenders TUI screenshot

Current Offenders dashboard using synthetic documentation data.

  • Export a committed report with e, or acquire one fresh CSV bundle with offenders export --period 30d (see Usage).
  • Press ? Help from any product screen for contextual controls and a concise in-app guide; Esc/q returns to your place.
  • Explore rolling history periods, live jail status, and IP/ASN/Country summaries.
  • Filter loaded results and investigate individual jails and IPs.
  • Review Coverage evidence and explicitly validate copy-only filter candidates.

Reports and investigation are read-only with respect to Fail2Ban configuration and bans. There is no ban/unban action or automatic Fail2Ban mutation. Coverage never installs filters/jails or enables/reloads Fail2Ban. Persistent application changes are limited to explicit or opt-in GeoIP data/policy under your XDG data root; validation also uses temporary local sample files.

Quick start

Supported baseline: Ubuntu 24.04 / Python >=3.12 / Fail2Ban >=1.0.2. Fail2Ban, readable logs, and narrowly scoped noninteractive sudo permissions must be supplied separately; see installation and permissions.

Install from PyPI and run:

pipx install offenders
offenders

GeoIP enrichment is optional. Installation downloads no databases; an explicit update fetches DB-IP Lite, and automatic updates require opt-in. See the GeoIP guide for lifecycle and attribution. Coverage analysis and validation are explicit, manual, and copy-only; a sample match never establishes filter safety. See Coverage.

Documentation

Operator documentation · PyPI · Releases · Changelog · Development · MIT license

Release files for offenders 0.3.0

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for offenders 0.3.0
File Size Uploaded
offenders-0.3.0.tar.gz 144.6 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for offenders 0.3.0
File Interpreter ABI Platform
offenders-0.3.0-py3-none-any.whl Python 3 none any Details

Total release size: 242.4 kB

Release files / offenders-0.3.0.tar.gz

Download URL offenders-0.3.0.tar.gz
Size 144.6 kB
Tags Source
SHA-256 checksum
How to use checksums
803565a5dd5d3b41353182ba803eecbc08797c3a8d6c98340f783deb47471aeb
BLAKE2b-256 checksum
How to use checksums
ae5b4a6929baa86adec70cd88191da4dd73b1e9afd9aef2c1b0926d3ff69d610
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Sep 28, 2026.

Transparency log

Release files / offenders-0.3.0-py3-none-any.whl

Download URL offenders-0.3.0-py3-none-any.whl
Size 97.8 kB
Tags Python 3
SHA-256 checksum
How to use checksums
4e1f4c31901f09bd97b89f0989be4572ba75935f50a6838a5baa3ccf0fc7a122
BLAKE2b-256 checksum
How to use checksums
07ffc98578af1b3c1a18f0a27aac6b166093f75c4d60c16642ca3b18d0dede23
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Sep 28, 2026.

Transparency log

Release history Release notifications | RSS feed

0.3.1

2 release files

This release

0.3.0 This release

2 release files

0.2.1

2 release files

0.2.0

2 release files

0.1.0

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page