Documentation
File integrity
The paths, the hashes, and the two cases where text travels.
Monitored paths
- /etc/passwd, /etc/shadow, /etc/group, /etc/gshadow
- /etc/ssh/sshd_config and /etc/ssh/sshd_config.d; /root/.ssh/authorized_keys and other authorized_keys files
- /etc/sudoers and /etc/sudoers.d
- /etc/crontab, /etc/cron.d, /var/spool/cron and per-user crontabs
- /etc/systemd/system units and timers, including the agent's own unit
- /etc/pam.d (sshd, common-auth, common-account, system-auth, password-auth)
- /etc/hosts, /etc/hostname, /etc/nsswitch.conf
- /usr/local/bin/security-agent
- Web roots for sites the server hosts, including WordPress core, plugins and themes
What a finding carries
Path, hash before and after. For persistence files (cron entries, sudoers, authorized_keys, systemd services and timers) the text before and after, within a small byte budget, never for binary content, and never on first sight: a restart records, it does not report.
Web-shell candidates
A file matching a web-shell rule is reported with path, size, SHA-256, the rule and its first 200 bytes, and screened automatically. Quarantine always waits for a person; restore never needs approval.
Reviewed against the implementation on 2026-09-20. Something wrong? Tell us.