Documentation

Threat detection

What the agent watches for, by signal, and how findings are rated.

Signals

Authentication
SSH failures and successes with username and source, counted per source; interactive sessions attributed to privilege-granting changes.
Processes
Any process executing from a world-writable temp directory (/tmp, /var/tmp, /dev/shm, /run/shm), deleted or not, with path and command line; hidden processes, ld.so.preload, new kernel modules, immutable files; CPU, memory or outbound volume above the server's own baseline for five consecutive reports.
Files
Hashes of the files that grant access; web roots; web-shell rules with a 200-byte excerpt for screening.
Network
Outbound connections to new destinations with the owning process; SYN flood and connection-exhaustion measurements; hidden connections.
Accounts and privilege
New accounts (attributed to the package or session that created them), sudo grants, setuid and capability binaries (cleared when dpkg -V or rpm -V vouches for them), SSH keys.
Posture
Pending updates, firewall state, disks, failed units, certificates, time sync, backups, SSH configuration.

Rating

One policy rates every finding with its context: a package-created account that verifies is low; a change inside a trusted administrator's own session is attributed to it; a finding about a state that is no longer true closes itself; a finding about a change is yours to acknowledge. See the detection coverage page for the catalogue.

Response

A finding proposes the safe action where one exists. Blocking an attacking address runs on its own on a server set to Automatic; every other action waits for approval.

Reviewed against the implementation on 2026-09-20. Something wrong? Tell us.

Trust Center