🔴 État live — secubox-deb
Repo actif
CyberMind-FR/secubox-deb
Base Debian bookworm · arm64 + amd64
Repo archivé
gkerma/secubox-openwrt
Abandonné — migration vers Debian terminée
Stack principal
FastAPI + sbxwaf (Go) + Debian bookworm
2995+ endpoints JWT · HAProxy/mitm · CrowdSec · apt.secubox.in (arm64 + amd64 signés)
Langages (secubox-deb)
Python 29.8%
JS 24.8%
HTML 23.8%
Shell 11%
CSS 6.6%
C 1.8%
Licence
CMSD-1.0
Source-disclosed · droits réservés · audits CESTI/CC autorisés sans accord préalable · CSPN-ready
ToolBoX publique — kbin
VILLAGE3B · Cabine Numérique
Diagnostic compromission iPhone gratuit · R0/R1/R2 opt-in · cartographie sociale « You Have Been Tracked » (JA4 + cookies tiers) · kbin.gk2.secubox.in
WAF actif — sbxwaf
mitm → CrowdSec → nft drop (~12 s)
Binaire Go statique · 37 Mo RSS · 231 vhosts · scale-to-zero · dashboard Menaces/Campagnes v2.41.0
SOC hiérarchique
soc-agent · soc-gateway · soc-web
Intel : device-intel · vortex-dns · vortex-firewall · ai-insights · antirootkit 0.1.1 (jail cgroup + nft)
🔄 Migration SecuBox-Deb — OpenWrt → Debian
"SecuBox aims to be a full operating system for a security tool — a Swiss army knife + modular OS appliance. Design philosophy : KISS."
— README.md · CyberMind-FR/secubox-deb · 2026Commits totaux
3 041
Depuis v1.0.0 · 24 mars 2026
Releases officielles
110+
v1.0.0 → v2.41.0 · migration 131/139 modules
Packages (v2.41.0)
124
185 assets · images système + Live USB + ISO
Repo APT
apt.secubox.in
bookworm main · arm64 + amd64 · GPG packages@secubox.in · SHA256SUMS.gpg
Releases
v2.41.0LATEST
SecuBox-DEB v2.41.0 — CyberMind Security Platform
20 août 2026 · 02:54 UTC · github-actions · 43c8053
124 packages · 185 assets · SOC hiérarchique (soc-agent/gateway/web) · Intel (device-intel, vortex-dns, vortex-firewall, ai-insights) · dashboard sbxwaf Menaces/Attaquants/Campagnes · antirootkit 0.1.1 · apps : mail, gitea, nextcloud, ollama, jellyfin, matrix
124 packages
SOC
sbxwaf
antirootkit
arm64 + amd64
secubox-mochabin-bookworm.img.gz (cible principale)
secubox-espressobin-v7 / ultra (arm64)
secubox-rpi-arm64-bookworm.img.gz (Pi 400 kiosk)
secubox-live-amd64 + installer ISO (UEFI/BIOS)
Boot : Live · Kiosk GUI · Console TUI · Bridge · Install · To RAM
Script QEMU arm64 (hôtes x86)
Web UI : https://:9443 (admin / secubox)
GPG packages@secubox.in · SHA256SUMS.gpg
v2.14–v2.20
Ligne système v2.x — consolidation été 2026
29 juin → 13 août 2026
Cadence continue (v2.14.0 → v2.20.0) · 124 packages stabilisés · profils Full/Lite/Media Lab/Secure Gateway · services intégrés : Nextcloud, mail + webmail, PeerTube, PhotoPrism, forge git, blog RSS — protégés WAF + MITM/DPI
Profiles webui→ctl
Services auto-hébergés
WAF + DPI
v2.13.x
Ligne principale v2.13 — APT arm64 + kiosk Pi 400
29 mai → juin 2026
v2.13.4 débloque la publication APT arm64 · v2.13.10 première image kiosk rpi400 fonctionnelle · v2.13.11/12 : masquage services + curseur X pour opération salon sur Pi 400 4 GB
APT arm64
Kiosk Pi 400
first-point POC
v2.2.1
Eye Remote — écran rond externe
11 mai 2026 · ligne parallèle
Pi Zero W + HyperPixel 2.1 Round (480×480) · gadget USB OTG composite (réseau + série) · cube 3D + anneau arc-en-ciel · métriques CPU/RAM/disque/temp/RSSI
HyperPixel Round
USB OTG
v1.3.0
SecuBox Installer ISO v1.3.0 — fin du sprint migration
30 mars 2026 · 05:13 UTC · bb34439
ISO Hybrid UEFI + Legacy BIOS · 51 packages · Preseed clone · AZERTY FR · TEST-001 → v1.3.0 en 7 jours sur 4 architectures
ISO Hybrid
Sprint 7 jours
v1.0.0
SecuBox Live USB v1.0.0 — fondation
24 mars 2026 · 17:08 UTC · gkerma · 6f6f366
Première image live amd64 · UEFI GRUB · SquashFS · persistence · 4 modes de boot
Fondation
SquashFS + GRUB
Architecture de migration
| OpenWrt / LuCI | Debian bookworm | |
|---|---|---|
| RPCD shell backend | → | FastAPI + Uvicorn (Unix socket) |
| UCI /etc/config/ | → | TOML /etc/secubox/secubox.conf |
| luci-app-* (JS/CSS/HTML) | → | Conservé + XHR réécrits |
| Paquets .ipk / opkg | → | Paquets .deb / apt + apt.secubox.in |
| 38 modules LuCI | → | 139 modules .deb (131 migrés) |
| OpenWrt buildroot | → | dpkg-buildpackage + GitHub Actions |
Installation rapide depuis le repo APT
curl -fsSL https://apt.secubox.in/install.sh | sudo bash
sudo apt install secubox-full # ou secubox-lite
📄 LA BOX — Le document fondateur (31 août 2021)
"Une boîtier avec une prise réseau et WiFi. Un relais entre Internet et le réseau personnel. Se protéger des intrusions malintentionnées."
— LA BOX, 31 août 2021↑ En Sortie
DNS filtrant · AdGuardHome
VPN sortant · Tor
Firewall nftables
DPI + QoS sortant
VPN sortant · Tor
Firewall nftables
DPI + QoS sortant
↓ En Entrée
IDS/IPS · CrowdSec
WAF HAProxy/mitmproxy
DMZ isolée
NAC · Auth captive portal
WAF HAProxy/mitmproxy
DMZ isolée
NAC · Auth captive portal
⏳ Timeline — De LA BOX au MirrorNet
2019–2023
Traversée du désert — WireGuard kernel (2020). Yggdrasil môrit. did:plc émerge. LocalAI naît.
31 août 2021
📄 LA BOX — Document fondateur — AdGuardHome, Tor, CrowdSec, DMZ. ESPRESSObin V7, OpenWrt 21.02, philosophie DIY.
2024–2025
SecuBox v0.1 → v0.17 — Fondations sécurité. CI/CD multi-arch. 38 modules LuCI. Stack OpenWrt.
Mars 2026
Sprint migration OpenWrt→Debian — TEST-001 → v1.3.0 en 7 jours sur 4 architectures. ISO Hybrid UEFI. FastAPI + apt.secubox.in. Licence CMSD-1.0.
Mai–Juin 2026
Ligne v2.x — APT arm64 signé, kiosk Pi 400, Eye Remote (écran rond USB OTG), 124 packages, grammaire CTL 8 couches, profils Full/Lite.
Juillet 2026
Services auto-hébergés complets (Nextcloud, mail, PeerTube, PhotoPrism, forge git) sous WAF + MITM/DPI · sbxwaf Go single-binary (231 vhosts, scale-to-zero) · OPAD formalisé.
Août 2026 — MAINTENANT
SecuBox-Deb v2.41.0 — 3 041 commits, 110+ releases, 139 modules (131 migrés), 2995+ endpoints. SOC hiérarchique, antirootkit, kbin ToolBoX VILLAGE3B + cartographie sociale « You Have Been Tracked ».
2026 Q4 →
MirrorNet — WireGuard mesh P2P + relais parallèles (Tor local) · pairs témoins Meshtastic (ancres ALERTE·DÉPÔT) · Matrix fédéré · did:plc · Tor quick-switch kbin (#683) · SecuBox Companion (PWA/APK) · CSPN.
github.com/CyberMind-FR/secubox-deb
· De LA BOX au MirrorNet — 2021–2026
🌐 MirrorNetworking — L'inversion du paradigme
"L'EnigmaBox promettait la décentralisation mais dépendait de serveurs centraux. SecuBox MirrorNet tient la promesse : aucun serveur central, jamais."
✗ EnigmaBox (2013–2019)
Exit servers centraux (SPOF)
VoIP via serveur central (écoutable)
cjdns décentralisé, infra centralisée
Dépendance cloud obligatoire
Identité liée au service central
✅ SecuBox MirrorNet (2026)
Zéro serveur central, zéro SPOF
WireGuard mesh + VoIP SRTP E2E
Chaque box = univers autonome
did:plc · Matrix fédéré · ALERTE·DÉPÔT
Chain of Hamiltonians · HamCoin
Pairs témoins Meshtastic · relais Tor locaux
🔧 Hardware — GlobalScale Technologies
Marvell Armada · Linux mainline · Debian arm64 officiel · <15W · FCC/CE
Espresso
ESPRESSObin V7
SoC A53 1.2GHz Dual
RAM 1–2 GB DDR4
Réseau WAN + 2×LAN DSA
Profil SecuBox Lite
Espresso Ultra
ESPRESSObin Ultra
SoC A53 1.2GHz Dual
RAM 2 GB DDR4 + eMMC
Réseau PoE + 4×LAN + WiFi
Profil SecuBox Lite+
Sheeva
Sheeva64 WiFi
RAM 1 GB + 4 GB eMMC
Réseau 2×GbE
Profil SecuBox Lite
Pi 400 / Pi 4
BCM2711 Quad
SoC A72 1.5–1.8GHz
RAM 2–8 GB
Réseau GbE + USB
Profil Lite · Kiosk par défaut
Pi 5
BCM2712 Quad 2.4GHz
RAM 4–8 GB
Réseau GbE + USB
Profil SecuBox Full
Eye Remote
Pi Zero W + HyperPixel 2.1 Round
Écran rond 480×480
Lien USB OTG (réseau + série)
Rôle dashboard satellite
MOCHAbin ★
Armada 7040 Quad
SoC A72 1.8GHz 4-core
RAM 4–8 GB DDR4
Réseau 2×SFP+ 10GbE + 4×GbE
Profil SecuBox Pro
VM x86_64 également supportée · VirtualBox / QEMU · 2+ GB RAM · Virtio/NAT ·
Profil : SecuBox Full
🏛 Certifications — Roadmap ANSSI CSPN
Documentation technique80%
Tests fonctionnels30%
Tests de sécurité20%
Audit code source10%
Évaluation CESTI0%
Visa ANSSI0%
Cible CSPN : SecuBox-Deb sur MOCHAbin · Périmètre WAF + IDS/IPS + VPN WireGuard · Évaluateur CESTI à identifier · Horizon : 2027
Licence CMSD-1.0 : audits par laboratoires accrédités (CESTI, équivalents CC) explicitement autorisés sans accord préalable.
Licence CMSD-1.0 : audits par laboratoires accrédités (CESTI, équivalents CC) explicitement autorisés sans accord préalable.