| Device | Protection | Connection | Activity today | Status |
|---|---|---|---|---|
| Saad-iPhone 10.13.13.4 | All traffic shielded · Private DNS · Ad/malware block · Spyware watch | Offline last seen 1d ago | 0 DNS lookups today · 23 MiB in / 77 MiB out | Protected — no problems. 0 ad/tracker/malware lookups blocked for this device today; nothing suspicious seen from it. |
| Saad-iPhone (backup DNS profile) 10.13.13.2 | DNS filtering only (ads/malware + spyware watch when this profile is in use) | Standby — not connected this profile has never dialled in | 0 DNS lookups today · 0 MiB in / 0 MiB out | No problems. This backup profile is not currently in use — Saad-iPhone runs on its full-tunnel profile instead. |
| Partner-phone 10.13.13.3 | DNS filtering only (ads/malware + spyware watch when this profile is in use) | Standby — not connected this profile has never dialled in | 0 DNS lookups today · 0 MiB in / 0 MiB out | No problems. This backup profile is not currently in use — Saad-iPhone runs on its full-tunnel profile instead. |
| Partner-iPhone-2 10.13.13.5 | All traffic shielded · Private DNS · Ad/malware block · Spyware watch | Offline last seen 1d ago | 0 DNS lookups today · 0 MiB in / 0 MiB out | Protected — no problems. 0 ad/tracker/malware lookups blocked for this device today; nothing suspicious seen from it. |
| Time (UTC) | Pri | Source | Signature |
|---|---|---|---|
| 10/01/2026-16:45:41.024411 | P2 | 195.184.76.24 | [1:2402000:7878] ET DROP Dshield Block Listed Source group 1 |
| 10/01/2026-16:45:41.024411 | P2 | 195.184.76.24 | [1:2403580:112108] ET CINS Active Threat Intelligence Poor Reputation IP group 281 |
| 10/01/2026-16:45:41.331472 | P2 | 91.231.89.251 | [1:2403450:112108] ET CINS Active Threat Intelligence Poor Reputation IP group 151 |
| 10/01/2026-16:46:12.995312 | P2 | 91.230.168.124 | [1:2403445:112108] ET CINS Active Threat Intelligence Poor Reputation IP group 146 |
| 10/01/2026-16:46:56.011200 | P2 | 91.230.168.233 | [1:2403446:112108] ET CINS Active Threat Intelligence Poor Reputation IP group 147 |
| 10/01/2026-16:48:23.534251 | P2 | 91.196.152.222 | [1:2403444:112108] ET CINS Active Threat Intelligence Poor Reputation IP group 145 |
| 10/01/2026-16:48:59.247575 | P3 | 91.108.121.200 | [1:2048911:4] ET INFO Observed DNS Over HTTPS Domain (dns .quad9 .net in TLS SNI) |
| 10/01/2026-16:49:50.048668 | P3 | 105.77.200.133 | [1:2210044:2] SURICATA STREAM Packet with invalid timestamp |
| Item | State | Detail |
|---|---|---|
| unattended-upgrades | 10h ago | 2026-10-01T06:42:14Z |
| OpenClaw gateway | pinned | diff-review before upgrade (monthly) |
| Skills | pinned | never blind-pull; re-review diffs |
| Component | Layer | Version / feed | Last | Cadence | Note |
|---|---|---|---|---|---|
| OpenClaw gateway | Platform | v2026.7.1 | 2026-07-19 | 30d | check latest stable monthly; pinned, diff-review before upgrade |
| VPS host OS | Platform | Debian | 2026-07-19 | 7d | apply security patches weekly |
| Skills (pinned) | Platform | pinned | 2026-07-25 | 30d | diff re-review before any `skills update` — never blind-pull |
| Mobile spyware DNS-watch | Detection | 1167 Amnesty IOCs | 2026-07-26 | 1d | WireGuard DNS-only + dnsmasq + spyware-dns-check; refresh 04:17 daily; alerts Saad on a hit |
| Ad/malware DNS blocker (OISD) | Network | 334k domains | 2026-07-26 | 1d | oisd-block.conf on wg0 dnsmasq; refresh 04:37 daily, validated + auto-rollback |
| WireGuard full-tunnel VPN | Network | wg0 10.13.13.0/24 | 2026-07-29 | 30d | personal VPN; all peer traffic egresses via VPS so Sentinel DNS-watch + OISD block + DoT apply to the phone; port 51820/udp; peers 10.13.13.2-.7; Noura .7 added 2026-07-29 (full-tunnel, preshared-key) |
| Encrypted upstream DNS (DoT) | Network | Quad9 TLS | 2026-07-26 | 30d | systemd-resolved DNSOverTLS strict; dnsmasq->127.0.0.53->Quad9:853; no plaintext leak (verified) |
| Canary tripwires | Detection | 3 decoy files | 2026-07-26 | 90d | sentinel-canary.service (inotify); WhatsApp alert on any open; log /var/log/sentinel-canary.log |
| Vaultwarden | Identity | self-hosted | 2026-07-26 | 30d | vault.91.108.121.200.sslip.io; signups disabled; nightly backup 03:15 |
| Restic offsite backup (VPS->Mac) | Resilience | restic 0.19.1 | 2026-07-26 | 1d | daily 10:00 pull to Saad Mac, encrypted, keep 14d/8w; WhatsApp alert on failure |
| Immutable backup mirror | Resilience | rest-server append-only | 2026-07-26 | 30d | 2nd Restic repo on Mac; nightly restic copy; deletes rejected 403 (ransomware insurance); verified |
| ufw firewall | Network | default-deny | 2026-07-26 | 30d | only 22, 80, 443, 51820/udp + wg0; verified vault/DNS/WG unaffected |
| fail2ban (sshd) | Network | systemd backend | 2026-07-26 | 30d | auto-bans SSH brute-force IPs |
| unattended-upgrades | Platform | security-only | 2026-07-26 | 1d | daily security patches, no auto-reboot; supersedes weekly-manual patching |
| AIDE file integrity | Detection | daily 05:07 | 2026-07-26 | 1d | alerts Saad on filesystem changes, auto-rebaselines after alert |
| rkhunter rootkit scan | Detection | weekly Sun 05:17 | 2026-07-26 | 7d | alerts Saad on warnings |
| Break-glass playbook | Human | doc v1 | 2026-07-26 | 180d | ~/Desktop/Jarvis docs/Sentinel-Break-Glass-Playbook.html; 6 incident runbooks; Saad to print |