Anubis ZTNA Gateway

Secure RDP, SSH, and OPC UA with a single Windows gateway.

Visit Website
July 18, 2026 Hardware dies. Config moves. Anubis doesn't care.

๐Ÿ› ๏ธ RTO < 60s:

Guest hardware dies? Just copy the config folder to the new box. ZTNA connectivity is back in under a minute. No reconfiguration. No network headaches. No production stop.

๐Ÿ”‘ Data at Rest:

Everything local is encrypted. Steal the config files? Good luck. They're useless without Anubis auth.

Simple. Secure. Fast.

Comment

July 11, 2026 Why Anubis ZTNA Is Different

Why Anubis Is Different

๐—ฅ๐—ฒ๐—ฎ๐—น-๐˜๐—ถ๐—บ๐—ฒ ๐—–๐—ผ๐—ป๐˜๐—ฟ๐—ผ๐—น:
Every request is verified on the fly, without exceptions. No access decision is made based on outdated information or cached data.

๐—ฃ๐—ฒ๐—ฟ-๐—จ๐˜€๐—ฒ๐—ฟ ๐—–๐—ฅ๐—Ÿ:
Granular and immediate revocations, not global. Each user has their own Certificate Revocation List, allowing targeted revocations without impacting the entire infrastructure.

๐—–๐—ฎ๐—ฐ๐—ต๐—ฒ๐—น๐—ฒ๐˜€๐˜€ ๐—ฃ๐—ผ๐—น๐—ถ๐—ฐ๐˜† ๐—˜๐—ป๐—ด๐—ถ๐—ป๐—ฒ:
ACL policies are always fresh and applied instantly. Changes take effect in real-time, with no propagation delays.

๐—”๐—–๐—Ÿ-๐—ฏ๐—ฎ๐˜€๐—ฒ๐—ฑ ๐—”๐—ฐ๐˜๐—ถ๐˜ƒ๐—ฒ ๐—ฆ๐—ฒ๐˜€๐˜€๐—ถ๐—ผ๐—ป ๐—ง๐—ฒ๐—ฟ๐—บ๐—ถ๐—ป๐—ฎ๐˜๐—ถ๐—ผ๐—ป:
Immediately terminates existing sessions upon block. The user loses access in less than 60 seconds, even with open tunnels.

๐—”๐—ด๐—ป๐—ผ๐˜€๐˜๐—ถ๐—ฐ ๐—”๐—ฟ๐—ฐ๐—ต๐—ถ๐˜๐—ฒ๐—ฐ๐˜๐˜‚๐—ฟ๐—ฒ:
Works on any network (EasyTier, ZeroTier, WireGuard). You're not locked into a specific vendor: Anubis adapts to your infrastructure, not the other way around.

###Community Edition Ready###

1 Comment

  1. 1

    Reading this, it feels like you're selling a philosophy of trust rather than a list of security features.

    The challenge is helping buyers immediately connect those architectural decisions to business outcomes. Most people don't buy "per-user CRLs"โ€”they buy confidence that access changes take effect exactly when they need them to.

July 8, 2026 The Dark Side of Anubis: Your Internet, Your Rules. ๐Ÿ‘€


With Anubis + EasyTier, you're not simply "protecting" your network.
You're creating your own parallel Internet.


Your DNS, resolve names however you want, without censorship, without intermediaries.

Your TLS, encrypt whatever you want, however you want.

Your mTLS, you decide who can talk to whom.

Zero exposed ports, your network doesn't exist for anyone who isn't supposed to see it.

Comment

July 8, 2026 Your VPN mesh isn't secure. Anubis is the missing layer.

Zero Trust is not a product. It's a different way of designing trust.

When I designed Anubis ZTNA, the question wasn't:

"How can I add another security control?"

The question was far more complex:

"How can I allow access to resources without turning the resources themselves into a target?"

Because in traditional architectures there is a contradiction:

  • More accessibility often means more exposure.

  • More security often means more complexity.

  • More centralization often means creating a single point of failure.

The solution was to separate what is normally concentrated.


๐Ÿ”น 100% On-Premise: where trust resides

Anubis was built on a precise principle:

Security must remain under the organization's control.

The architecture can be installed entirely within the customer's infrastructure.

Identity, policies, operational PKI, mTLS certificates, and access enforcement all remain under the control of the protected environment.

No mandatory dependency on a cloud control plane.

For critical infrastructure, OT, and regulated environments, the question isn't just:

"How do we protect the data?"

but also:

"Where does the trust that decides who can access reside?"


๐Ÿ”น Anubis Core: autonomous on-premise security

Each Anubis Gateway can operate autonomously directly within the customer's infrastructure.

The Gateway maintains locally:

  • Cryptographic identities

  • Operational PKI

  • mTLS certificates

  • Secure channels

  • Policy enforcement

  • Local resource protection

With an extremely small footprint, Anubis is designed to be lightweight, portable, and deployable close to the resources it protects.

Security stays close to the resource that needs to be protected.


๐Ÿ”น GT_MANAGER: Enterprise on-premise orchestration

For organizations that require multi-Gateway and multi-tenant management, GT_MANAGER introduces a higher level of administration.

It does not replace the Gateway.

It coordinates it.

It manages:

  • Users

  • Tenants

  • PBAC policies

  • Configuration distribution

  • Authorization synchronization

Each user is evaluated individually through their own attribute- and context-based policy.

Not static groups.

Not inherited permissions.

Each identity has its own access rule.


๐Ÿ”น Centralized Policy. Distributed Enforcement.

GT_MANAGER governs policy distribution.

Anubis Gateways enforce the rules locally.

Cryptographic trust remains distributed across the Gateways, where mTLS, operational PKI, and secure channels are managed directly.


But the most important point about Zero Trust is this:

Authentication must not be the moment when permanent trust is born.

A session authorized today can become unauthorized tomorrow.

A certificate can be revoked.

A policy can change.

A time window can expire.

A user can lose access rights while still connected.

For this reason, Anubis applies continuous context verification.

During a session, the following are re-evaluated:

  • Identity

  • Certificate status

  • Time constraints

  • PBAC policies

If authorization conditions are no longer met, access is revoked without waiting for the session to close naturally.


๐Ÿ”น Controlled Application Exposure

Anubis does not directly expose protected services.

The exposed ports belong exclusively to the Anubis layer.

The Gateway manages:

  • Multi-host TLS endpoints

  • System-generated HTTPS certificates

  • Hostnames via internal DNS

  • Controlled application publishing

The real service remains isolated.

The resource is not exposed.

Only the control point is exposed.


๐Ÿ”น Overlay Native Architecture

Anubis operates within a private overlay network.

The overlay provides connectivity.

Anubis provides:

  • Identity

  • Policy

  • Control

  • Enforcement

This separation makes it possible to protect even environments where modifying existing systems is complex or impossible:

  • Legacy servers

  • OT infrastructure

  • PLCs

  • Industrial machinery

  • Critical systems


Zero Trust doesn't mean building more walls.

It means designing systems where trust is never granted permanently.

Trust is not granted. Trust is continuously verified.


#CyberSecurity #ZeroTrust #ZTNA #OTSecurity #NIS2 #PKI #mTLS #CriticalInfrastructure #IndustrialCybersecurity #NetworkSecurity #AnubisZTNA

Comment

July 7, 2026 Zero Trust in 5 Minutes on Windows 10+
  1. Register user (with OTP/TOTP)

  2. Sign mTLS certificate (with USB Bunker)

  3. Configure tunnel (RDP, SSH, OPC UA...)

  4. Apply time-based policies (hours, days, expiration)

  5. Reload configuration (no restart needed)

Tunnel active with dual authentication (mTLS + OTP) and PBAC policies. No cloud dependencies.

Comment

July 6, 2026 Anubis, lightweight Windows gateway for legacy XP/PLC systems (free CE)

Hi everyone,

I'm a cybersecurity dev working in IT/OT environments. I kept running into the same problem: ZeroTier and Tailscale handle the mesh just fine, but remote access to legacy systems (XP, PLCs) is still a pain, especially revocation. Rebuilding the PKI every time a contractor left was getting old.

So I built Anubis, a lightweight Windows gateway (15MB) that sits on top of the mesh and handles MFA, remote access (RDP, SSH, OPC UA,HTTP,TCP_RAW), and one-click revocation at the application layer.

No cloud, no open ports, no touching the legacy boxes.

Community Edition is free for personal use.

Would love to get feedback from anyone dealing with similar environments, especially on the revocation model.


Site: https://sgneep.com/anubis/download.php

Thanks for taking a look!

17 Comments

  1. 1

    I like that you built around an existing workflow instead of asking people to replace it. For legacy systems, reducing operational friction is often more valuable than adding new features. I'm curious which part caused the most resistance in early testing: deployment, security reviews, or user adoption?

    1. 1

      Thanks for your interest. Building the core was fairly painless. Even the security checks are excellent. The library vulnerability scan is run once a month. The prof tests are excellent. Fortunately, I used "cybersec by design" in this code from the early stages of development. The greatest resistance was in writing the client-side UX, where users expect to enter a password and log in.

  2. 1

    The revocation angle is stronger than you might realize because it maps directly to an audit question: every SOC 2 and CMMC assessment asks how contractor access gets terminated, and most OT shops have no good answer. I run a compliance company for SMBs and that single control failure shows up constantly. Position Anubis as the answer to the offboarding finding, not as another ZTNA tool, and the buyers with budget will find you.

    1. 1

      Your advice on positioning Anubis as 'offboarding-first' rather than just another ZTNA tool is gold, I'm definitely going to use it. Thanks again!

  3. 1

    How long did it take you to make it?

    1. 1

      It took me about a year, and I worked on it an average of 12 hours a day. It took a lot of effort and resources.

  4. 1

    This is a cool niche to build for. The one-click revocation angle stood out to me since that's a pain point I don't see discussed much.

    I'd also add a simple real-world example on the landing pageโ€”it'd make the value click much faster for people outside the IT/OT space.

    1. 1

      Thanks, I'll add it as soon as possible

  5. 1

    "Rebuilding the PKI every time a contractor left was getting old." ๐Ÿ‘ โ€” This is like having to rekey your house every time a plumber leaves, and the plumber still has the master key because you never trust the damn lock.

    The New Yorkerโ€™s 2024 piece on "Legacy Infrastructure as a Human Condition" noted, "Security is not a feature, itโ€™s the environment we live in." The author didnโ€™t say "itโ€™s a pain," they said "itโ€™s the air you breathe."

  6. 1

    What stood out to me is that you're treating revocation as the core problem rather than remote access itself.

    A lot of tools make it easy to grant access. The harder operational challenge is removing that access quickly and confidently without disrupting legacy systems. Solving that lifecycle problem feels like a much stronger long-term position than competing on connectivity alone.

    1. 1

      thanks for your feedback

      1. 1

        I'm curious about one thing.

        As you've been building it, has the biggest challenge turned out to be the technical side of revocation, or getting customers to recognize that revocation is the problem they actually need to solve?

        Those usually lead to very different products, which is why I wondered.

  7. 1

    The "no touching the legacy boxes" part is what caught my attention. Anyone who's had to keep old XP or PLC systems alive knows exactly why that matters.

    I can imagine an OT admin hearing the name from a colleague then quietly looking it up before ever suggesting it internally. For something that sits between contractors and critical systems that first impression carries a lot more weight than the feature list.

    Have you had anyone outside your own network try it in a real environment yet or are you still collecting feedback before people put it into production?

    1. 1

      Thanks, we just launched the Community Edition, it's live and already being used by several external users. For the production-ready version, we're currently running tests and gathering feedback before the full release.

      1. 1

        That's a good stage to be in. I'm curious have you thought about how people might discover Anubis through AI assistants? It feels like this is the kind of niche tool someone finds after asking ChatGPT something like 'how do I securely access legacy XP or PLC systems without exposing them to the internet?

        1. 1

          no, I haven't thought about it yet

          1. 1

            That actually makes sense. I think most technical founders naturally focus first on building, testing, and getting real users rather than thinking about discovery channels.

            The reason I brought it up is because Anubis is solving a very specific problem. Those are often the kinds of problems people search for through AI assistants when they don't even know the right tool exists yet.

            I'm curious are most of your current users finding Anubis through communities/referrals, or are you already seeing people discover it through search?

July 6, 2026 mTLS, SNI Protection, and OTP: The Anubis Security Stack

Most VPNs and remote access tools weren't built for the strict security needs of industrial environments. That's why I built Anubis: a Zero Trust Network Access solution that combines an overlay mesh with application-layer security. Hereโ€™s how the architecture works...

Here's the complete architecture of Anubis ZTNA:

1. Overlay Mesh Network (10.144.144.0/24)

Anubis leverages ZeroTier to create a private, secure overlay network where each node (like 10.144.144.7 for the Access Agent) connects seamlessly. This isolates sensitive traffic from the underlying physical network, making it invisible to external observers. ZeroTier provides the reliable mesh backbone, while Anubis adds the Zero Trust security layer on top.

2. Access Agent & Whitelist

The agent listening on 127.0.0.1 (localhost) acts as a gateway for local applications. The whitelist with SHA256 process verification ensures only authorized programs can establish connections, no unauthorized executables allowed.

3. mTLS and SNI Protection

All communications are secured with mTLS (Mutual TLS) using standard P12/PFX certificates. SNI protection (Server Name Indication) hides domains like vnc.server.local and rdp.server.local, making it impossible for external observers to identify which services you're using.

4. Access Ports & Services

Each service is exposed on dedicated ports (e.g., 34001 for RDP, 34002 for SSH, 8443 for HTTPS, 42444 for OPC UA). Connections arrive at 127.0.0.1:xxxx on the agent, creating an isolated tunnel for each protocol.

5. Security Layer (ACL, CRL, TOTP)

  • ACL (Access Control List) with time constraints (start-end, days, expires, enabled/disable within 60 seconds) for temporary access

  • CRL (Certificate Revocation List) for instantly revoking compromised certificates

  • Token BOR (Burn On Read) the token is consumed on first use, preventing replay attacks

6. Anubis Core (Sidecar Mode)

The Anubis core runs in sidecar mode alongside your services on a dedicated server. It handles authentication, encryption, and traffic routing without interfering with your existing infrastructure.

Comment

About

I'm a cybersecurity software developer, and Anubis is my latest project. The Community Edition is now live and ready for download.