Documentation

File integrity

The paths, the hashes, and the two cases where text travels.

Monitored paths

  • /etc/passwd, /etc/shadow, /etc/group, /etc/gshadow
  • /etc/ssh/sshd_config and /etc/ssh/sshd_config.d; /root/.ssh/authorized_keys and other authorized_keys files
  • /etc/sudoers and /etc/sudoers.d
  • /etc/crontab, /etc/cron.d, /var/spool/cron and per-user crontabs
  • /etc/systemd/system units and timers, including the agent's own unit
  • /etc/pam.d (sshd, common-auth, common-account, system-auth, password-auth)
  • /etc/hosts, /etc/hostname, /etc/nsswitch.conf
  • /usr/local/bin/security-agent
  • Web roots for sites the server hosts, including WordPress core, plugins and themes

What a finding carries

Path, hash before and after. For persistence files (cron entries, sudoers, authorized_keys, systemd services and timers) the text before and after, within a small byte budget, never for binary content, and never on first sight: a restart records, it does not report.

Web-shell candidates

A file matching a web-shell rule is reported with path, size, SHA-256, the rule and its first 200 bytes, and screened automatically. Quarantine always waits for a person; restore never needs approval.

Reviewed against the implementation on 2026-09-20. Something wrong? Tell us.

Trust Center