Evidence tier Source Confirmed · 8 captures on record
What the publisher says
As described on Microsoft Marketplace.
sish is a free and open-source, self-hosted SSH-based reverse tunneling server that enables users to securely expose local applications and services to the internet through SSH connections. Designed to be lightweight and command-line based, sish provides reverse TCP, HTTP, and HTTPS tunneling capabilities, making it useful for remote access, application testing, development, demonstrations, and securely sharing locally hosted services without requiring complex network configuration.
Key Features of sish:
Show the rest of the publisher’s description (33 more lines)
- Free and open-source SSH-based reverse tunneling server.
- Allows users to expose local applications and services through secure SSH connections.
- Supports reverse TCP tunneling for accessing local TCP services remotely.
- Supports HTTP and HTTPS tunneling for exposing local web applications.
- Provides custom subdomain support for HTTP and HTTPS tunnels.
- Supports SSH public-key authentication for secure access control.
- Provides command-line based operation with lightweight resource requirements.
- Can be used for development, testing, debugging, demonstrations, and remote access.
- Can run as a standalone binary or as a systemd service on Linux servers.
- Suitable for developers, system administrators, DevOps teams, and organizations that need secure reverse tunneling capabilities.
sish Usage:
$ sudo su
$ cd /opt/sish
# Check the installed sish version
$ ./sish-server --version
# Check sish help and available options
$ ./sish-server --help
# Check the sish binary
$ ls -lh /opt/sish/sish-server
# Check the sish binary type
$ file /opt/sish/sish-server
# Check the sish source/release version
$ git describe --tags --always
# Check available sish releases/tags
$ git tag --sort=-version:refname | head
# Start the sish server manually
$ ./sish-server
# Check sish systemd service status
$ systemctl status sish
# Restart the sish service
$ systemctl restart sish
Disclaimer:
sish is an open-source project maintained by its community of contributors. This content is provided for informational purposes only. We are not affiliated with or endorsed by the sish project maintainers. All trademarks, logos, and product names are the property of their respective owners.
Agent build and provenance
See the full provenance
The layer-by-layer build, the evidence behind each claim, the risk basis and the cross-marketplace links are open to any account. Some rows are disclosed, some the source leaves Unknown; a free account shows you which.
Compliance
- FedRAMPConfirmedNot listed90%, registry-checkedNo FedRAMP Marketplace entry matched this vendor's domain, checked 2026-08-27registry recordas observed 2026-08-27
Confirmed means matched to a public authoritative registry. Claimed means the vendor or its listing states it, not yet cross-checked. A framework not shown was not found in any source we hold, which is not evidence against it. Not listed means a scoped registry check found no match for this vendor's domain: a No is a scoped registry check, not a compliance judgment. Confidence bands: 95% domain-verified, 90% registry-checked, 80% self-attested, 70% weak signal. Self-attested items marked “vendor's site” are gathered from the vendor's own website and are not verified by us.
Vendor
External enrichment · as of 2026-08-29
Reconciled on 9/3/2026
Sources
Publisher resources
1 linkLinked repositories
Unknown means this listing does not publish a repository. It is not a statement that the code is closed, and a linked repository is not a claim that the publisher wrote it: the registry computes that relationship privately and does not publish it.
Evidence risk is the share of the build you cannot see before you deploy, not a security rating. Sign in to see the layer-by-layer basis for this band.

