Both zero-dependency (stdlib http.server + urllib), consistent with the project's no-dependency-tree stance for a security daemon. Web dashboard (enodia_sentinel/web.py + static/dashboard.html): - read-only JSON API over the log dir: /api/status, /api/alerts, /api/alerts/<id>, /api/events - bearer-token auth (constant-time; header or ?token=), required on non- loopback binds, auto-generated + persisted (0600) when unset - binds the host's Tailscale IP by default (auto-detected), reachable from the tailnet but not the LAN/internet - self-contained dark SPA: severity cards, live alert list, full snapshot viewer; 10s auto-refresh - path-traversal-safe alert lookup; `enodia-sentinel web` subcommand; daemon now writes a pidfile so the dashboard can show live status - hardened enodia-sentinel-web.service (read-only, no caps) Phone push (enodia_sentinel/notify/): - pluggable backends — ntfy, Pushover, generic webhook — each separating a pure build() (unit-tested, no network) from send() - a backend turns on when its config keys are set; pushes gated by notify_min_severity; severity → per-service priority/tags - fired from snapshot.capture on worker threads, errors swallowed - desktop notify-send retained Tests: +16 (9 web incl. a real-server 401/200 auth test, 7 notify request-build cases). 55/55 pass. Live end-to-end verified: daemon → alert → API → page. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
29 lines
1.4 KiB
Bash
29 lines
1.4 KiB
Bash
# Maintainer: Enodia
|
|
pkgname=enodia-sentinel
|
|
pkgver=0.4.0
|
|
pkgrel=1
|
|
pkgdesc="Host intrusion-detection daemon — signature-based detection of reverse shells, LD_PRELOAD rootkits, fileless malware, and persistence tampering"
|
|
arch=('any')
|
|
url="https://github.com/Enodia/enodia-sentinel"
|
|
license=('GPL-3.0-or-later')
|
|
depends=('python>=3.11' 'iproute2' 'procps-ng')
|
|
optdepends=('python-bpfcc: eBPF event-driven execve monitor (catches short-lived processes)'
|
|
'bpftrace: execve tracing of short-lived processes in snapshots'
|
|
'libnotify: desktop notifications on alert')
|
|
backup=('etc/enodia-sentinel.toml')
|
|
source=()
|
|
sha256sums=()
|
|
|
|
package() {
|
|
cd "$startdir/.."
|
|
# Install the stdlib-only package as a directory + launcher under /usr.
|
|
install -d "$pkgdir/usr/lib/enodia-sentinel"
|
|
cp -r enodia_sentinel "$pkgdir/usr/lib/enodia-sentinel/"
|
|
install -Dm755 packaging/enodia-sentinel.wrapper "$pkgdir/usr/bin/enodia-sentinel"
|
|
install -Dm755 src/sentinel-redteam "$pkgdir/usr/bin/sentinel-redteam"
|
|
install -Dm644 systemd/enodia-sentinel.service "$pkgdir/usr/lib/systemd/system/enodia-sentinel.service"
|
|
install -Dm644 systemd/enodia-sentinel-web.service "$pkgdir/usr/lib/systemd/system/enodia-sentinel-web.service"
|
|
install -Dm644 config/enodia-sentinel.toml "$pkgdir/etc/enodia-sentinel.toml"
|
|
install -Dm644 LICENSE "$pkgdir/usr/share/licenses/$pkgname/LICENSE"
|
|
install -dm750 "$pkgdir/var/log/enodia-sentinel"
|
|
}
|