product image
product image

RuleHawk

$29/ month
14 day trial

Self-hosted firewall auditor — find shadowed, permissive & drifting rules

The rule that was meant to protect you, and doesn’t. A deny added after an incident sits below a years-old partner permit covering the same range — so it never fires. Reading the ACL top to bottom never shows it.

Features

  • Four checks on an exported config: shadowed/duplicate rules, permissive rules, hygiene, drift from a baseline
  • Worst-first findings; every finding names the rule and the fix
  • Lines it cannot parse become a finding, never a silent drop
  • Vendors: iptables/nftables, Cisco ASA, pfSense/OPNsense, FortiGate (FTD/Palo Alto on the roadmap)
  • Audits rules as written, not packet flow; fully offline
  • Four sample configs ship free (ASA sample: 11 findings, 2 high)

Server requirements

  • Linux, macOS or Windows (amd64 and arm64); single static binary. Public Docker image hexward/rulehawk is the free edition; Pro/Team use the licensed binary
  • Measured: ~10 MB binary, ~10 MB RAM idle, SQLite file — no database server
  • Minimum host: 1 vCPU, 512 MB RAM, 200 MB disk
  • Dashboard 127.0.0.1:8426; no network access needed at all

Tiers. Free (Apache-2.0): 1 config, all checks, webhook+syslog, 30-day history. Pro: 25 configs, scan-now, email/Slack/Telegram, 1-year history. Team: unlimited, multi-user, PagerDuty/Teams. 14-day trial (card required; first charge day 15).

Delivery. Automatic: key by Whop DM after checkout; download in the Downloads tab.

Whop sells paid licences only. Free: github.com/nizartuanku/rulehawk