X.A.N.D.E.R

X.A.N.D.E.R

Xenomorphic Adaptive Network Defense & Emergency Response โ€” the home sentinel.

Local-first ยท Private by design ยท Watches every device, all the time

In active development โ€” not yet released
Follow the build on Discord

Solo dev ยท A guardian for the network you live on

A guardian that learns your network
and never sends it anywhere.

Xander runs entirely on your own machine. It studies the devices on your network, learns what normal looks like, and raises the alarm when something changes โ€” without a cloud account, a subscription, or a single byte of your home leaving the house.

A sentinel, not a checkbox

Xander sweeps your network on a heartbeat, baselining every device it finds. The simulation below is a small taste โ€” in the real dashboard you watch live scans, anomalies, and posture shifts as they happen.

live simulation โ€” the sweep baselines trusted devices; a flare is an anomaly being graded
Trusted device Sentinel sweep Anomaly Known-bad / threat intel

Not antivirus. A network immune system.

Typical home securityX.A.N.D.E.R
Protects one device at a timeWatches the whole network as one organism
Static signature listsLearns a behavioral baseline for every device
One fixed sensitivityShifts posture as threat pressure rises
Cloud accounts & telemetryRuns entirely on your machine
Black-box verdictsEvery action graded, logged, and auditable
Acts first, asks neverHigh-severity actions need approval before they fire

The watch never stops

๐Ÿ›ฐ๏ธ

Discovers everything

An ARP and ping sweep finds every device on your network; an Nmap port scan fingerprints the services each one is running. New device on the network? Xander knows within a heartbeat.

๐Ÿง 

Learns what's normal

Every device gets a behavioral baseline โ€” its usual open ports, services, uptime, and identity. Detection is statistical, not a fixed list, so it adapts to your home instead of a generic one.

๐Ÿ“ˆ

Scores anomalies

When a device drifts from its baseline โ€” new ports, unexpected services, a flipped uptime pattern, a spoofed identity โ€” Xander grades the deviation and rates its severity from info to critical.

๐ŸฆŽ

Shifts its posture

Xenomorphic by design: as anomaly pressure rises, Xander tightens from Normal to Vigilant to Lockdown โ€” scanning more often, raising sensitivity, and demanding approval before it acts.

๐ŸŒ

Knows the known-bad

Free public threat-intelligence feeds flag any device matching a known botnet or criminal netblock. The lists refresh on their own and keep working even when the internet doesn't.

๐Ÿฉน

Finds the holes

Optional CVE matching checks the exact service versions on your network against known vulnerabilities, graded by severity โ€” so you learn that the old camera firmware is a real risk, not a guess.

๐Ÿค–

Local-first AI

An on-device LLM (via Ollama or LM Studio) reasons about suspicious findings, with a rule-based fallback when it's offline. No cloud keys โ€” and device names and banners can never trick it into standing down.

๐Ÿ”—

Connects the dots

A campaign correlator links isolated low-severity events โ€” repeated probes, a subnet sweep, a multi-stage pattern โ€” into a single picture, so a slow, quiet attack doesn't slip by one alert at a time.

โœ‹

Asks before it acts

Sensitive actions like blocking a device run through an approval chain. A dry-run mode lets you watch what it would do before you ever let it touch the network.

๐Ÿ“œ

Remembers honestly

Every scan, alert, block, and approval is written to a separate, append-only audit trail โ€” no edits, no deletes. You can always answer "what did it do, and why?"

๐Ÿ“ฒ

Reaches you anywhere

A real-time dashboard shows the live alert feed, and high-severity events push to your phone over ntfy or Discord โ€” so you're warned even when no one's watching the screen.

๐Ÿ 

Local-first, forever

Plain Python and SQLite, running on a spare PC or a Raspberry Pi. No accounts, no telemetry, no subscription. Your network's data is yours and stays on your hardware.

The xenomorphic posture system

A defense that always behaves the same way is a defense an attacker can plan around. Xander reads the pressure on your network and changes its own behavior to match โ€” calmer when all is quiet, relentless when it isn't:

Normal โ€” calm, hourly watch โ†’ Vigilant โ€” scans faster, sensitivity up โ†’ Lockdown โ€” relentless, approval for every block โ†’ Maintenance โ€” operator-held, actions paused

By design.

Your home network is a map of your life โ€” what you own, when you're home, who visits. A tool meant to protect it should never become one more thing watching you. Things Xander will never do:

  • Send your network data to the cloud
  • Require an account
  • Phone home
  • Sell or mine your data
  • Block a device without a graded reason
  • Take a high-severity action without approval
  • Hide what it did from the audit log

Built, watching, not yet public

The sentinel is real and running today โ€” discovery, behavioral baselines, anomaly scoring, the posture system, threat-intel feeds, local AI analysis, campaign correlation, approval chains, the audit trail, and a live dashboard, with a growing test suite behind every promise on this page. It's part of the Ares Realm family alongside L.U.C.Y and E.E.V.E.E. A public release will come when it's worthy of guarding a home. Until then, the forge is open on Discord.

Want a guardian that's actually yours?

X.A.N.D.E.R is built by Ares Realm Studios for the people who'll run it on their own networks. Come watch it grow, ask questions, or tell us what your home defense should never do.