🛡 LYNIS security audit RKHUNTER malware scan WAZUH + AUDITD SIEM + forensics OPENSNITCH app firewall TAILSCALE zero trust VPN SURICATA + ZEEK + ntopng · deep inspection ADGUARD + UNBOUND private DNS chain CROWDSEC threat intelligence UFW + FAIL2BAN perimeter MPDC RV BRAIN 9-LAYER SECURITY ARCHITECTURE · v1.0 LYNIS SCORE: 65/100

I Built an Enterprise-Grade Security Stack on a $200 Repurposed Desktop — Here's What I Learned

There's a moment in every serious IT project where you step back, look at what you've built, and think "wait… did we actually just do that?"

I had that moment today.

The Project

I've been building what I call the MPDC RV Brain — a fully hardened, self-hosted network security stack running on a repurposed Dell OptiPlex 5050 (Intel i7-7700, 32GB RAM, Debian 12). The goal: build a paranoid, production-grade security infrastructure for a mobile RV network before a single IoT device ever touches it.

Build the cage first. Then put the animals in it.

What We Built

In a single marathon session, the following stack went from zero to fully operational:

9 Independent Layers of Defense (H3)

Layer 1 — Network Perimeter UFW firewall + fail2ban. The outermost wall. Unwanted traffic never even gets to knock on the door.

Layer 2 — Threat Intelligence CrowdSec with nftables enforcement. Crowdsourced threat intelligence shared across millions of global installations. If an IP attacked someone in Paris this morning, it's blocked here before it ever tries us.

Layer 3 — Private DNS AdGuard Home + Unbound in a chained architecture. Every DNS query on the network is intercepted, filtered for malicious and tracking domains, then resolved privately against root DNS servers — completely bypassing upstream providers like Google or Cloudflare. Zero query visibility to third parties.

Layer 4 — Deep Packet Inspection Suricata (signature-based IDS) + Zeek (behavioral analysis) + ntopng (real-time traffic visualization) running simultaneously. Three tools, two completely different detection methodologies, watching every packet on the wire.

Layer 5 — Zero Trust VPN Tailscale mesh network connecting all owned devices. Remote access without a single open port to the internet.

Layer 6 — Application Firewall OpenSnitch interrogates every single outbound connection attempt from every process on the machine. Nothing phones home without explicit permission.

Layer 7 — SIEM + Kernel Audit Wazuh manager + agent + auditd. Complete forensic trail of every file change, login, process, and syscall. If something gets through every other layer, Wazuh tells you exactly what it did and when.

Layer 8 — Malware Scanning rkhunter performing periodic deep rootkit and malware signature scanning.

Layer 9 — Security Auditing Lynis continuous hardening audits with a quantified hardening score. Baseline established: 65/100 on day one — and climbing.

The Architecture

An attack has to survive all 9 layers to get anywhere. Here's what it faces:

① UFW + fail2ban — blocked at the port level before it even lands ② CrowdSec — blocked if the IP is on the global threat blacklist ③ AdGuard + Unbound — blocked if the domain is known malicious ④ Suricata + Zeek — flagged if the traffic pattern looks suspicious ⑤ Tailscale — encrypted mesh ensures only trusted devices communicate ⑥ OpenSnitch — blocked if no process has permission to make that connection ⑦ Wazuh + auditd — every action logged and alerted on in real time ⑧ rkhunter — confirms no persistence or rootkit was established ⑨ Lynis — audits the gap and tells you how to close it next time

4 different detection methodologies. 9 independent layers. That's not a network — that's a fortress.

The Hard Parts

I won't pretend it was smooth sailing. Real talk from the trenches:

Pi-hole v6 breaking changes — spent hours debugging before abandoning it entirely for AdGuard Home. Sometimes the right call is to pivot, not persist.

DNS chain debugging — getting AdGuard → Unbound chained correctly across Docker host networking required deep understanding of how containers share network namespaces. Port conflicts are sneaky.

CrowdSec bouncer connectivity — a containerized LAPI needs explicit port exposure to talk to a host-level bouncer. Obvious in hindsight, invisible until it bites you.

Wazuh version pinning — agent version must be ≤ manager version. Learned that the hard way.

Every one of those debugging sessions taught something that will make the next deployment dramatically faster.

Why This Matters for IoT

The RV network will eventually host a full fleet of IoT devices — sensors, cameras, environmental monitors, smart systems. Every single one of those devices is a potential attack vector. Many of them phone home to manufacturer servers with data you never consented to share.

By building this infrastructure before the first device arrives, every new addition to the network enters a fully audited, fully monitored environment where:

Its DNS queries are logged and filtered Its network behavior is analyzed by Suricata and Zeek Its outbound connections require explicit approval via OpenSnitch Any anomalous behavior triggers Wazuh alerts immediately

That's not paranoia. That's professional network hygiene.

What's Next

The security foundation is complete. Next phases:

Node-RED automation flows — tying security events into the broader RV automation system

Grafana dashboards — visualizing the full security picture in real time

AI Stack — local LLM (Ollama) + Whisper for voice, with the security stack feeding an intelligent layer that correlates events, explains anomalies in plain English, and eventually makes autonomous decisions

The goal: a self-healing, self-explaining network that gets smarter over time.

The Takeaway

You don't need an enterprise budget to build enterprise-grade security. You need:

A repurposed desktop ($0-200) Docker and some patience A methodical layered approach A willingness to debug when things break (and they will)

The homelab community has built incredible open-source tooling. CrowdSec, Suricata, Zeek, Wazuh, AdGuard — every tool in this stack is free. The only cost is time and curiosity.

Build the cage first. The animals can wait.

Currently unemployed and building cool things. If you're working on interesting infrastructure, security, or IoT projects and want to connect — let's talk.

Originally published on LinkedIn

So I was bored over the weekend...

MPDC — MOBILE SECURITY PLATFORM · PARANOIDRV Cloudflare cortex.mpdc.dev · vault.mpdc.dev Tailscale mesh none-ya.business cloudflared tunnel → localhost Chris — root any device · anywhere T3600 · office-console · classified.and.hardened CORTEX API :7777 · /brain · /knowledge /propose · /execute cortex_update daemon · 60s poll cortex.db SQLite · single truth LiteLLM router fast · smart · genius 8b → 14b → Claude Node-RED :1880 · nervous system flows · automation Mosquitto MQTT :1883 · sensor bus SECURITY SOC Suricata Zeek Wazuh CrowdSec AdGuard Unbound ntopng Tor Vaultwarden vault.mpdc.dev Grafana :3000 · dashboards InfluxDB :8086 · telemetry Open WebUI :3002 · Aria UI Kokoro TTS · voice Proxmox VE VM 101 · Ollama · DeepSeek 8b/14b · CUDA WireGuard · Wazuh · LiteLLM security perimeter · threat response ARIA — NODE 2 · Mac Studio M1 Max · INCOMING · negotiating as we speak Aria — 32b engine Ollama · M1 Max 32GB unified memory · Metal ~11-15 tok/sec LiteLLM bridge Phase 2 · tool middleware Node-RED integration MQTT awareness CORTEX tools brain · propose · execute commit approval layer Chris holds the trigger GL-X3000 cellular router not-telling-you.local · LAN gateway · cellular uplink LEGEND CORTEX memory layer AI routing automation services Aria — incoming threat detection MPDC · PARANOIDRV · BUILT IN A 40FT RV · FROM SCRATCH · IN ONE WEEK github: coming soon · mpdc.dev