I submitted this a few months ago and has undergone some major changes since then, adding:
- bandwidth monitoring
- a dashboard for showing plots
- support for storing logs off-system to mitigate some forms of tampering, and depending on your threat model could also be used by a router to cutoff network access for compromised devices
- overhaul hashing to reduce failures, other than a few cases outlined in the readme, hash failures should be seen as a sign of suspicious activity (I may be able to make use of ima_file_hash for future improvements?)