Skip to content
All security projects
Security projectDemo readyEndpoint threat hunting

GhostWire Sentinel

Endpoint threat hunting agent for Linux devices, kiosks, and edge systems — detects stealth persistence, baseline drift, suspicious outbound behavior, and silent attacker tradecraft.

Captures a security-relevant snapshot of a Linux host (processes, services, cron jobs, SSH keys, outbound connections) and compares it to an approved baseline to detect drift. Runs anomaly, beaconing, and persistence detectors on the live snapshot for immediate alerts. Built for Linux kiosks, signage players, IoT/edge devices, and unattended servers where silent backdoors are the primary threat.

PythonLinux agentBaseline driftPersistence detection

Catalog entry only — a full write-up lands closer to release.

Related across catalogs

Want a heads-up when GhostWire Sentinel releases?

Subscribe via blog