enodia-sentinal/enodia_sentinel
Luna dbbe35b3fc Add baseline reconciliation: accept audited drift with a reason
Implements the v0.9 roadmap item from the approved design spec. Operators
accept a specific FIM/package/listener/SUID drift item with a mandatory
reason; the ack suppresses that one alert only while the live state still
matches the recorded fingerprint. Content kinds (fim/pkgfile) re-alert on
further change; identity kinds (listener/suid) retire on TTL or revoke.

- reconcile.py: ReconcileStore (mtime-cached, fails closed on missing/corrupt
  store), fingerprint builders, and the filter_alerts chokepoint.
- CLI: baseline accept/revoke/list with --reason/--expires/--force/--stale/--json.
- Wired at the daemon sweep + eBPF chokepoint, fim-check, and /api/integrity.
- RECONCILE_V1 schema, config knob, COMMAND_REFERENCE/SCHEMAS/OPERATIONS/ROADMAP
  docs, and reconcile unit/CLI/integration tests.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-06-27 10:33:55 -07:00
..
detectors Add memory obfuscation and ps-hidden process detection 2026-06-13 03:55:09 -07:00
events Add event-driven memory syscall telemetry 2026-06-13 05:45:30 -07:00
notify Add read-only web dashboard and phone push notifications 2026-05-31 16:18:00 -07:00
static Add dashboard integrity/watchdog console 2026-06-18 17:39:53 -07:00
__init__.py Frame Sentinel as IDS IPS and EDR 2026-06-13 05:59:03 -07:00
alert.py Add event-driven eBPF execve layer with a Snort-style rule engine 2026-05-31 07:16:53 -07:00
cli.py Add baseline reconciliation: accept audited drift with a reason 2026-06-27 10:33:55 -07:00
config.py Add baseline reconciliation: accept audited drift with a reason 2026-06-27 10:33:55 -07:00
daemon.py Add baseline reconciliation: accept audited drift with a reason 2026-06-27 10:33:55 -07:00
fim.py Add baseline reconciliation: accept audited drift with a reason 2026-06-27 10:33:55 -07:00
incident.py Add stable v1 schema IDs and docs 2026-06-16 04:05:12 -07:00
netutil.py Relicense under GPL-3.0-or-later 2026-05-31 06:52:34 -07:00
pkgdb.py Add platform docs; reposition as host security platform 2026-06-10 04:03:06 -07:00
posture.py Add systemd unit posture checks 2026-06-19 02:27:19 -07:00
provenance.py Add false-positive triage via package-ownership provenance 2026-05-31 22:05:00 -07:00
reconcile.py Add baseline reconciliation: accept audited drift with a reason 2026-06-27 10:33:55 -07:00
respond.py Add stable v1 schema IDs and docs 2026-06-16 04:05:12 -07:00
rootcheck.py Add memory obfuscation and ps-hidden process detection 2026-06-13 03:55:09 -07:00
ruleops.py Generate event rule documentation 2026-06-15 18:52:28 -07:00
schemas.py Add baseline reconciliation: accept audited drift with a reason 2026-06-27 10:33:55 -07:00
selfprotect.py Add HTTPS management console and response planning 2026-06-12 02:39:53 -07:00
snapshot.py Add stable v1 schema IDs and docs 2026-06-16 04:05:12 -07:00
system.py Add memory obfuscation and ps-hidden process detection 2026-06-13 03:55:09 -07:00
triage.py Add false-positive triage via package-ownership provenance 2026-05-31 22:05:00 -07:00
web.py Add baseline reconciliation: accept audited drift with a reason 2026-06-27 10:33:55 -07:00