
An eBPF-powered Active Defense system that turns your Linux server into a deceptive honeypot. Features transparent traffic redirection, OS fingerprint spoofing, kernel-level DLP, and Zero Trust SSH access (SPA).
Phantom Grid is a next-generation Zero Trust Network Access (ZTNA) and active defense system. It operates at both the Kernel Level (eBPF) and Application Level (mTLS) to transform Linux servers into a robust, deceptive attack surface.
Built for modern enterprises, it is designed to significantly reduce the visibility of your infrastructure to network scanners while remaining highly accessible to authorized personnel.
Critical network services (e.g., SSH, Database, Management interfaces) are dropped natively in the Linux Kernel via XDP by default, strongly mitigating the risk of unauthorized discovery. Access is dynamically granted via Single Packet Authorization (SPA) utilizing Ed25519 cryptography and Time-Based One-Time Passwords (TOTP).
To mitigate NAT Blindspots, Phantom Grid features an integrated Mutual TLS (mTLS) Proxy. The proxy strictly verifies client-side X.509 certificates before routing any traffic, ensuring robust protection even if an attacker shares the same Public NAT IP as an authorized user.
Phantom Grid seamlessly integrates with existing Microservices architectures without disrupting internal backend-to-database communication:
lo) operates natively with zero overhead, allowing backend services and databases on the same host to communicate freely while the public port remains cloaked.CN=backend-api) rather than unreliable IP addresses, ensuring true Zero Trust in dynamic Cloud/Kubernetes environments.Designed for enterprise scale, the Fleet Manager includes a KDC API that automatically generates SPA Keys, TOTP secrets, and mTLS certificates for new deployments. The Agent supports loading a large volume of Public Keys, allowing rapid revocation of individual access without affecting the fleet.
The SPA Client includes an embedded, hardware-accelerated Web Dashboard. Users can easily connect to protected servers, view real-time latency, and manage connection states with a single click without requiring CLI proficiency.
Phantom Grid leverages the Linux eBPF verifier to significantly reduce the risk of kernel instability compared with traditional kernel modules. Programs that fail verifier validation are rejected before loading into the kernel.
By operating at the XDP layer, Phantom Grid achieves negligible performance overhead. CPU utilization during high-volume attacks (e.g., DDoS) is significantly reduced compared to packet processing in the traditional Linux networking stack, while maintaining minimal memory usage.
graph TD
Client[Remote Client] -->|SPA Packet| XDP{eBPF XDP Cloaking}
Client -->|mTLS Handshake| Proxy{mTLS Proxy}
subgraph Kernel Space
XDP -->|Invalid/Scan| Redirect[Redirect to Honeypot]
XDP -->|Valid SPA| Allow[Open Port for IP]
TC[eBPF TC Hook] -->|Egress Filtering| NIC
end
subgraph User Space
Allow --> Proxy
Proxy -->|Invalid Cert| Reject[Terminate Connection]
Proxy -->|Valid Cert| Service[Internal Service e.g. SSH:22]
Redirect --> HP[Internal Honeypot]
HP --> Telemetry[Logger & Telemetry]
end
Fleet[Fleet Manager] -.->|Provisions| ClientOur eBPF-based architecture operates drastically faster than traditional iptables or nftables by dropping packets at the NIC driver level before they enter the Linux network stack.
iptables rules which typically bottleneck around 2-3 Mpps under similar CPU constraints.Enterprise security products require absolute stability. Phantom Grid is rigorously validated to ensure zero disruption to production environments:
To ensure optimal performance and security, the following minimum requirements must be met:
libbpf1, systemd.We provide production-ready Debian packages for Debian/Ubuntu environments, fully integrated with systemd for auto-recovery.
# Install the Debian package
sudo dpkg -i build/deb_phantom-grid_1.0.0_amd64.deb
# Enable and start the Agent (Defense System)
sudo systemctl enable --now phantom-agent
# Enable and start the Fleet Manager (Control Center)
sudo systemctl enable --now phantom-fleet
To compile the enterprise package from source:
git clone https://github.com/haidang-infosec/phantom-grid.git
cd phantom-grid
# Install build dependencies
sudo apt update && sudo apt install -y clang llvm libbpf-dev golang-go make git gcc-multilib linux-libc-dev
# Build the Debian package
make package
The output will be generated at build/deb_phantom-grid_1.0.0_amd64.deb.
sudo phantom-grid \
-interface eth0 \
-spa-mode asymmetric \
-spa-key-dir /etc/phantom/keys \
-mtls -mtls-port 8443 -mtls-target 22
Start the client application to access the Web UI:
spa-client -web-ui -ui-port 9090
Navigate to http://localhost:9090 to manage your connections.
To achieve strong parity with enterprise-grade solutions, the following features are actively being developed for upcoming releases:
Phantom Grid operates under an Open Core / Dual License model.
Commercial usage of the enterprise features requires a valid paid license. For purchasing and enterprise support, please contact the sales team. See the LICENSE file for full details.