product image
product image

Hexward Suite

$99/ month
14 day trial

Six Hexward tools in one suite — self-hosted, from TLS monitoring to SIEM

Six self-hosted security tools in one suite, ~40% off buying separately.

  • CertLight — TLS expiry and weak-config monitoring
  • Attack Surface Monitor — what you expose, diffed daily
  • Decoy — canary tokens and honeypots, silent until touched
  • Patchlight — CVE triage by real exploitation evidence
  • RuleHawk — firewall audit: shadowed, permissive and drifting rules
  • Loglight — SIEM-lite: detections correlated into incidents

They work as a system. Every tool emits findings as syslog to Loglight; a Decoy trip from an address Loglight saw scanning becomes one critical incident.

Server requirements (all six on one host)

  • Linux x86-64; six static binaries (~10 MB each) or Docker; each keeps its own SQLite file — no database server
  • Measured idle: ~10 MB RAM per tool, ~60 MB for all six
  • Minimum host: 2 vCPU, 2 GB RAM, 10 GB disk; only Loglight’s retention grows — 20+ GB at 10 sources
  • Ports 8422-8427 (localhost by default) + Decoy honeypots and Loglight listeners

Suite Pro $99/mo (vs $164) — every tool at Pro. Suite Team $299/mo (vs $544) — every tool at Team: unlimited scale, multi-user, PagerDuty/MS Teams. 14-day trial on both. RuleForge, DmarcWatch, TenantWatch, AuditLight and TopoLight are sold separately.

Offline activation; an expired key drops to free limits.

Delivery. Automatic: keys by Whop DM; downloads in the Downloads tab.

Whop sells paid licences only. Free editions: github.com/nizartuanku